High severityNVD Advisory· Published Aug 30, 2025· Updated Apr 15, 2026
CVE-2012-10062
CVE-2012-10062
Description
A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload and execute arbitrary PHP code. The WebDAV service, accessible via /webdav/, accepts HTTP PUT requests using default credentials. This permits attackers to upload a malicious PHP payload and trigger its execution via a subsequent GET request, resulting in remote code execution on the server.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
1- Metasploit Wrap-Up 04/25/2026Rapid7 Blog · Apr 24, 2026