Skip to content

Latest commit

 

History

History
268 lines (216 loc) · 14.2 KB

README.md

File metadata and controls

268 lines (216 loc) · 14.2 KB
Published date: 2025-01-10 | Updated date: 2025-01-11 | Neustradamus

Should we use?
XAMPP

Apache + MariaDB + PHP + Perl

Linux / Apple MacOS / Microsoft Windows

Development use?
Production use?

XAMPP Logo

XAMPP Windows Interface

XAMPP, what is it?

XAMPP is a free and open-source cross-platform web server solution stack package developed by Apache Friends, consisting mainly of the Apache HTTP Server, MariaDB database, and interpreters for scripts written in the PHP and Perl programming languages.
Since most actual web server deployments use the same components as XAMPP, it makes transitioning from a local test server to a live server possible.

The Apache Friends website indicates that XAMPP stands for "XAMPP Apache + MariaDB + PHP + Perl", making it a recursive acronym. XAMPP formerly used MySQL, but this was replaced with MariaDB on 19 October 2015 and beginning with XAMPP versions 5.5.30 and 5.6.14, altering the meaning of the acronym. It originally stood for Cross-Platform + Apache + MySQL + PHP + Perl.

Source: Wikipedia

Important informations, a little history...

XAMPP and Apache Friends have been created by Kai "Oswald" Seidler and Kay Vogelgesang in 2002.
In 2013, Apache Friends has been acquired by Bitrock, creator of Bitnami.
In 2019, Bitrock has been acquired by VMware.
In 2022, Bitrock has been acquired by Backstaff Software without Bitnami.
In 2023, VMware has been acquired by Broadcom.

Updates?

Badly, since several years ago, there were little updates of XAMPP, it was already not good.
And nothing since 2023 after the sale of VMware.

Development use or Production use or boths?

Since 2002, XAMPP is used in development as well as in production on internal, external, and cloud machines. Attention: If it is not very often updated, there is no security.

Download statistics?

On Sourceforge:

It is only Sourceforge, there are not external download statistics.

Latest Apache Friends Announcement (2023-11-19)

Vulnerabilities

Some CVEs have been solved in latest used software versions
XAMPP has not up-to-date latest software versions

XAMPP
Apache HTTPd
MariaDB (10.4.x: EOL)
PHP (8.0.x and 8.1.x: EOL)
Apache mod_perl, Perl and StrawberryPerl
Apache Tomcat (8.5.x: EOL)
phpMyAdmin
FileZilla Server
Mercury Mail Transport System
OpenSSL (1.1.1: EOL / 3.1.x EOL Q1 2025)
Curl
Apache Portable Runtime - APR
Apache Portable Runtime Utility Library - APR-utils
FPDF
  • Not listed (no vulnerability?)
FreeTDS
FreeType
LibGD
GNU dbm
  • Not listed (no vulnerability?)
gettext
ICU4C
UW IMAP
  • Not listed (no vulnerability?)
Apache HTTP Request Library - apreq
Expat - libexpat
libpng
libxml
libxslt
mcrypt
mhash
  • Not listed (no vulnerability?)
Ming - libming
ncurses
OpenLDAP (client)
R&OS Pdf Class
  • Not listed (no vulnerability?)
ProFTPD
Sablotron
  • Not listed (no vulnerability?)
zlib

References

Softwares

Companies

Solutions

Author of this security alert

Neustradamus
Fediverse/Mastodon [email protected]
AT Protocol/Bluesky neustradamus.bsky.social
X/Twitter Neustradamus
Reddit Neustradamus
Hacker News Neustradamus
Published date: 2025-01-10 | Updated date: 2025-01-11 | Neustradamus