CVE-2013-2586: XSS
Published Sep 29, 2014
·Updated
XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripting (XSS) attacks via the WriteIntoLocalDisk method.
Affected Software
1 affected component
Apachefriends Xampp=1.8.1
Event History
Sep 29, 2014
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2586?
CVE-2013-2586 is considered a moderate severity vulnerability due to unauthorized access that can lead to cross-site scripting (XSS) attacks.
2
How do I fix CVE-2013-2586?
To fix CVE-2013-2586, restrict access to xampp/lang.php and ensure proper configuration of file permissions.
3
What types of attacks can be executed through CVE-2013-2586?
CVE-2013-2586 can be exploited to execute cross-site scripting (XSS) attacks via modification of the xampp/lang.tmp file.
4
Which versions of XAMPP are affected by CVE-2013-2586?
CVE-2013-2586 specifically affects XAMPP version 1.8.1.
5
Is CVE-2013-2586 a remote vulnerability?
Yes, CVE-2013-2586 is a remote vulnerability that allows attackers to exploit it from a distant location.