CVE-2007-2079 describes a remote buffer overflow vulnerability in XAMPP for Windows versions 1.6.0a and earlier. This flaw exists within the ADONewConnection Connect function in adodb.php, which improperly handles untrusted input for the database server hostname. With a CVSS score of 9.3, this vulnerability is critical, allowing remote attackers to execute arbitrary code with high impact on confidentiality, integrity, and availability, albeit with medium attack complexity. While not actively exploited in the wild (no KEV entry), public exploit code exists, specifically an ExploitDB entry for Metasploit, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.0aCPE matchmatch criteria | cpe:2.3:a:xampp:apache_distribution:*:*:windows:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.