EasyPHP - '/index.php' Authentication Bypass / Remote PHP Code Injection



EKU-ID: 42832 CVE: OSVDB-ID:
Author: KedAns-Dz Published: 2013-04-09 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/58945/info

EasyPHP is prone to an authentication bypass and a PHP code execution vulnerability.

Attackers may exploit these issues to gain unauthorized access to the affected application and perform arbitrary actions or execute arbitrary PHP code within the context of the web server process. Successful attacks can compromise the affected application and possibly the underlying computer.

EasyPHP 12.1 is vulnerable; other versions may also be affected.

http://www.example.com/home/index.php?to=ext

http://www.example.com/home/index.php?to=phpinfo