vendor:
EasyPHP Web Server
by:
KedAns-Dz
7.5
CVSS
HIGH
Arbitrary File Download
22
CWE
Product Name: EasyPHP Web Server
Affected Version From: 5.3.5.0
Affected Version To: 5.3.5.0
Patch Exists: NO
Related CWE:
CPE: easyphp:5.3.5.0
Platforms Tested: Windows
2011
EasyPHP Web Server 5.3.5.0 Remote File Download Exploit
EasyPHP is prone to a vulnerability that lets attackers to download arbitrary files because the application fails to sufficiently sanitize user-supplied input. An attacker can exploit this issue to download arbitrary files within the context of the webserver process. Information obtained may aid in further attacks.
Mitigation:
The vendor should release a patch to sanitize user-supplied input to prevent arbitrary file downloads.