CVE-2009-0919: High severity Apachefriends Xampp vulnerability

Published Mar 16, 2009
·
Updated

XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password for the "root" account within the included MySQL installation, (3) a blank default password for the "pma" account within the phpMyAdmin installation, and possibly other unspecified passwords. NOTE: this was originally reported as a problem in DFLabs PTK, but this issue affects any product that is installed within the XAMPP environment, and should not be viewed as a vulnerability within that product. NOTE: DFLabs states that PTK is intended for use in a laboratory with "no contact from / to internet."

Affected Software

109 affected components
Apachefriends Xampp=1.4.9
Apachefriends Xampp=1.5.0
Apachefriends Xampp=1.5.2
Apachefriends Xampp=1.4.3
Apachefriends Xampp=1.4.12
Apachefriends Xampp=0.6.3
Apachefriends Xampp=1.6.0
Apachefriends Xampp=1.0.1
Apachefriends Xampp=1.0
Apachefriends Xampp=1.4.3
Apachefriends Xampp=0.6.2
Apachefriends Xampp=0.3
Apachefriends Xampp=1.4.11
Apachefriends Xampp=1.4.11
Apachefriends Xampp=1.7.1
Apachefriends Xampp=0.6-beta
Apachefriends Xampp=1.6.4
Apachefriends Xampp=1.4.15
Apachefriends Xampp=0.7.4
Apachefriends Xampp=1.5.4a
Apachefriends Xampp=1.4.6
Apachefriends Xampp=development
Apachefriends Xampp=1.7
Apachefriends Xampp=1.6.5
Apachefriends Xampp=1.4.14
Apachefriends Xampp=0.9
Apachefriends Xampp=1.6.2
Apachefriends Xampp=1.5.1
Apachefriends Xampp=0.2-beta
Apachefriends Xampp=1.4
Apachefriends Xampp=1.4.8
Apachefriends Xampp=0.5-beta
Apachefriends Xampp=1.7.1
Apachefriends Xampp=1.2
Apachefriends Xampp=0.5
Apachefriends Xampp=1.5.5
Apachefriends Xampp=1.4.15
Apachefriends Xampp=1.4.12
Apachefriends Xampp=1.6.1
Apachefriends Xampp=1.5.1
Apachefriends Xampp=1.6.7
Apachefriends Xampp=0.9
Apachefriends Xampp=1.5.4
Apachefriends Xampp=1.4.4
Apachefriends Xampp=1.6.3
Apachefriends Xampp=1.5.5
Apachefriends Xampp=0.1-beta
Apachefriends Xampp=0.2-alpha
Apachefriends Xampp=1.4.5
Apachefriends Xampp=1.6.4
Apachefriends Xampp=1.4.7
Apachefriends Xampp=1.6.6
Apachefriends Xampp=1.5.3
Apachefriends Xampp=1.4.2
Apachefriends Xampp=0.7.1
Apachefriends Xampp=1.5.3
Apachefriends Xampp=1.4.13
Apachefriends Xampp=0.1-alpha
Apachefriends Xampp=0.6a
Apachefriends Xampp=1.4.7
Apachefriends Xampp=1.4.6
Apachefriends Xampp=1.6.8a
Apachefriends Xampp=1.5.4
Apachefriends Xampp=1.4.2
Apachefriends Xampp=1.6.5a
Apachefriends Xampp=0.7.2
Apachefriends Xampp=1.6.3
Apachefriends Xampp=0.4-alpha
Apachefriends Xampp=1.7
Apachefriends Xampp=1.6
Apachefriends Xampp=1.4
Apachefriends Xampp=1.4.4
Apachefriends Xampp=1.2
Apachefriends Xampp=1.4.10
Apachefriends Xampp=1.4.10
Apachefriends Xampp=1.6.6
Apachefriends Xampp=0.4
Apachefriends Xampp=1.6.1
Apachefriends Xampp=1.6.3a
Apachefriends Xampp=1.3
Apachefriends Xampp=1.4.13
Apachefriends Xampp=1.5.4a
Apachefriends Xampp=1.4.9
Apachefriends Xampp=1.4.16
Apachefriends Xampp=1.6.7
Apachefriends Xampp=0.7.0
Apachefriends Xampp=1.6.6a
Apachefriends Xampp=0.3-alpha
Apachefriends Xampp=1.5.2
Apachefriends Xampp=1.4.8
Apachefriends Xampp=0.6.1
Apachefriends Xampp=1.6.5
Apachefriends Xampp=1.4.5
Apachefriends Xampp=1.5
Apachefriends Xampp=0.8.1
Apachefriends Xampp=1.6.3a
Apachefriends Xampp=1.1
Apachefriends Xampp=0.8.2
Apachefriends Xampp=1.4.14
Apachefriends Xampp=1.6.0a
Apachefriends Xampp=0.6
Apachefriends Xampp=1.5.5a
Apachefriends Xampp=1.6.2
Apachefriends Xampp=0.7-beta
Apachefriends Xampp=1.3
Apachefriends Xampp=1.6.3b
Apachefriends Xampp=1.4.16
Apachefriends Xampp=0.7.3
Apachefriends Xampp=1.6.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Set a non-default, strong password for the 'nobody' account used by the bundled ProFTPD; replace the default 'lampp' password immediately.

    ProFTPD (included in XAMPP) password for 'nobody' account = change from 'lampp' to a strong unique password (not 'lampp')
  2. Configuration

    Configure a non-empty, strong password for the MySQL 'root' account to replace the blank default.

    MySQL (included in XAMPP) root account password = set a non-empty strong password (not blank)
  3. Configuration

    Set a non-empty, strong password for the 'pma' account used by phpMyAdmin to replace the blank default.

    phpMyAdmin (included in XAMPP) pma account password = set a non-empty strong password (not blank)
  4. Configuration

    Audit all services and applications installed within the XAMPP environment for default or blank credentials and change each to a unique strong password.

    XAMPP-installed components default/blank passwords = replace any default or blank passwords with strong, unique passwords
  5. Compensating control

    Use XAMPP only in an isolated laboratory environment with no contact from/to the internet; restrict inbound and outbound network access to XAMPP hosts via firewall rules or network segmentation so services are only reachable from trusted lab networks.

Event History

Mar 16, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:30 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2009-0919?

CVE-2009-0919 has a medium severity level due to the use of insecure default passwords in XAMPP installations.

2

How do I fix CVE-2009-0919?

To fix CVE-2009-0919, change the default passwords for the 'nobody' and 'root' accounts in XAMPP.

3

What versions of XAMPP are affected by CVE-2009-0919?

CVE-2009-0919 affects multiple versions of XAMPP, including 1.4.3, 1.4.9, 1.5.0, 1.5.2, and several others.

4

Can CVE-2009-0919 be exploited remotely?

Yes, CVE-2009-0919 can be exploited remotely due to the insecure default passwords on XAMPP installations.

5

What should I do if I am using an affected version of XAMPP?

If using an affected version of XAMPP, you should update to a secure version and change any insecure default passwords.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203