CVE-2013-2586
XAMPP 1.8.1 - Cross-Site Scripting via WriteIntoLocalDisk Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-2586. PoCs published by Manuel García Cárdenas.
AI-analyzed exploit summary This advisory describes a local write access vulnerability in XAMPP 1.8.1, where an unprivileged user can modify the 'lang.tmp' file via the '/xampp/lang.php' page. The proof of concept involves a simple HTTP request to demonstrate the file modification.
Description
XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripting (XSS) attacks via the WriteIntoLocalDisk method.
Exploits (1)
This advisory describes a local write access vulnerability in XAMPP 1.8.1, where an unprivileged user can modify the 'lang.tmp' file via the '/xampp/lang.php' page. The proof of concept involves a simple HTTP request to demonstrate the file modification.