CVE-2012-10062

A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload and execute arbitrary PHP code. The WebDAV service, accessible via /webdav/, accepts HTTP PUT requests using default credentials. This permits attackers to upload a malicious PHP payload and trigger its execution via a subsequent GET request, resulting in remote code execution on the server.
CVSS

No CVSS.

Configurations

No configuration.

History

30 Aug 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-30 14:15

Updated : 2025-09-02 15:55


NVD link : CVE-2012-10062

Mitre link : CVE-2012-10062

CVE.ORG link : CVE-2012-10062


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function

CWE-434

Unrestricted Upload of File with Dangerous Type