The page used to change the administrative password in XAMPP version 1.7.2 has no access restrictions in place.
632fd915fb3a1632c5e4271b01e7efb96cc07878cde952d35948092a5c19524d
______ __ ______
/\ == \ /\ \ /\ __ \
\ \ __< \ \ \ \ \ \/\ \
\ \_____\ \ \_\ \ \_____\
\/_____/ \/_/ \/_____/
[#]----------------------------------------------------------------[#]
#
# [x] XAMPP 1.7.2 Change Administrative Password
# [x] Author : bi0
# [x] Contact : bukibv@hotmail.com
# [+] Download : http://www.apachefriends.org/en/xampp-windows.html
#
[#]----------------------------------------------------------------[#]
#
# [x] Exploit :
#
# At the older versions of xampp "xamppsecurity.php" was allowed
# only for localhost but at version 1.7.2 i accessible by all
#
# http://example.com/security/xamppsecurity.php
#
# And you can change the .htacces user & pass and the phpMyAdmin pass
#
[#]----------------------------------------------------------------[#]
#
# Demo :
#
# [+] http://www.rrp.demokritos.gr/security/xamppsecurity.php
#
#
#
[#]----------------------------------------------------------------[#]