Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: Critical PHP Vulnerability Found in XAMPP
Newsletter
Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: Critical PHP Vulnerability Found in XAMPP
Newsletter
Search
  • Latest Stories
  • Security & Tech
    • Security
    • Vulnerabilities
    • Dark Web
    • Technology
    • Privacy
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
© MRS Media Company. Hackerdose LLC. All Rights Reserved.

Vulnerabilities » Critical PHP Vulnerability Found in XAMPP

Vulnerabilities

Critical PHP Vulnerability Found in XAMPP

A new vulnerability in XAMPP has been identified, which enables attackers to gain control of systems that are running PHP in CGI mode. This issue primarily impacts Windows-based installations that are configured to use Chinese or Japanese languages.

Marco Rizal
Last updated: August 21, 2024 10:20 am
By Marco Rizal - Editor, Journalist 2 Min Read
Share
PHP XAMPP Vulnerability
SHARE

A new bug has been discovered in XAMPP, a widely used utility for rapidly configuring web servers.

Security expert Orange Tsai tweeted about it, stating that it is a default feature of XAMPP that impacts PHP.

This flaw has the potential to allow malicious individuals to gain control of your computer if it is operating in CGI mode with PHP and XAMPP.

XAMPP is used by many administrators and developers to operate web servers that incorporate Apache, PHP, and other tools.

This vulnerability is severe in that it has the potential to enable remote code execution (RCE), which enables an adversary to execute any command on your system.

The problem has been observed exclusively in PHP installations that operate in CGI mode and are based on Windows.

It impacts computers that are configured to operate in Japanese or Chinese (both simplified and traditional).

However, the security expert cautions that other languages may also be at risk and recommends that all users update to the most recent PHP version, which has resolved the issue.

Orange Tsai discovered that the flaw enables attackers to deceive the system into believing that a special character is a standard one.

This character, referred to as a soft hyphen, has the potential to introduce detrimental commands. This is due to the fact that PHP fails to properly convert these characters from Unicode to ASCII.

Usually, PHP safeguards against malicious commands by using escape sequences to obscure hazardous characters.

However, in this case, a soft hyphen (which appears to be a standard dash but is not) can circumvent this safeguard.

The soft hyphen is interpreted by PHP as a genuine hyphen, which permits the execution of detrimental commands.

The good news is that a solution is readily accessible. It is recommended that all individuals promptly update their PHP installations.

This is particularly critical for individuals who are utilizing the affected Chinese or Japanese settings, as the flaw is straightforward to exploit.

Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our newsletter

Receive the latest news and stories straight to your inbox.

Latest stories

Bitcoin Holds at $85K as Global Trade Tensions and Fed Speculation Unfold

April 15, 2025

Michael Saylor Doubles Down on Bitcoin (BTC) with $285M Investment Amid Global Uncertainty

April 14, 2025

Mantra Faces Crisis After OM Token Crashes 90% in a Day

April 14, 2025

Solana (SOL) on the Verge of a Breakout: Could $300 Be the Next Target?

April 14, 2025

You might also like

ATM Machine Hacked to Show Hill Climb Racing Instead of Transactions

ATM Machine Hacked to Show Hill Climb Racing Instead of Transactions

Critical Wordpress Vulnerabilities

Critical WordPress Vulnerabilities and Malicious Plugin Infections

How a YouTube vulnerability can be used to steal files

How a YouTube Vulnerability Can Be Used to Steal Files

Hugging Face Chat Platform Vulnerabilities Exposed in New Security Research

Hugging Face Chat Platform Vulnerabilities Exposed in New Security Research

Newsletter

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site

Quick Links

  • Contact Us
  • Search
  • Malware
  • Downloads

Company

  • About Us
  • Terms and Conditions
  • Cookies Policy
  • Privacy Policy
Advertise with us

Socials

Follow Us

© 2025 | HackerDose Media Company – All Rights Reserved

Welcome Back!

Sign in to your account

Lost your password?