EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root by bypassing SecurityManager restrictions. Attackers can send GET requests with encoded directory traversal sequences like /..%5c..%5c to read system files such as /windows/win.ini.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root by bypassing SecurityManager restrictions. Attackers can send GET requests with encoded directory traversal sequences like /..%5c..%5c to read system files such as /windows/win.ini. | |
| Title | EasyPHP Webserver 14.1 Path Traversal via Directory Traversal Sequences | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-18T21:19:22.540Z
Reserved: 2025-12-16T19:22:09.998Z
Link: CVE-2023-53944
Updated: 2025-12-18T20:18:10.327Z
Status : Received
Published: 2025-12-18T20:15:53.097
Modified: 2025-12-18T22:15:54.863
Link: CVE-2023-53944
No data.
OpenCVE Enrichment
No data.