header-logo
Suggest Exploit
vendor:
EasyPHP
by:
SecurityFocus
7,5
CVSS
HIGH
Authentication Bypass and PHP Code Execution
287
CWE
Product Name: EasyPHP
Affected Version From: 12.1
Affected Version To: 12.1
Patch Exists: YES
Related CWE: N/A
CPE: a:easyphp:easyphp
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013

EasyPHP Authentication Bypass and PHP Code Execution Vulnerability

EasyPHP is prone to an authentication bypass and a PHP code execution vulnerability. Attackers may exploit these issues to gain unauthorized access to the affected application and perform arbitrary actions or execute arbitrary PHP code within the context of the web server process. Successful attacks can compromise the affected application and possibly the underlying computer.

Mitigation:

Users should upgrade to the latest version of EasyPHP to mitigate this vulnerability.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/58945/info

EasyPHP is prone to an authentication bypass and a PHP code execution vulnerability.

Attackers may exploit these issues to gain unauthorized access to the affected application and perform arbitrary actions or execute arbitrary PHP code within the context of the web server process. Successful attacks can compromise the affected application and possibly the underlying computer.

EasyPHP 12.1 is vulnerable; other versions may also be affected. 

http://www.example.com/home/index.php?to=ext

http://www.example.com/home/index.php?to=phpinfo