EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root by bypassing SecurityManager restrictions. Attackers can send GET requests with encoded directory traversal sequences like /..%5c..%5c to read system files such as /windows/win.ini.
History

Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Easyphp
Easyphp webserver
Microsoft
Microsoft windows
Vendors & Products Easyphp
Easyphp webserver
Microsoft
Microsoft windows

Thu, 18 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 20:00:00 +0000

Type Values Removed Values Added
Description EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root by bypassing SecurityManager restrictions. Attackers can send GET requests with encoded directory traversal sequences like /..%5c..%5c to read system files such as /windows/win.ini.
Title EasyPHP Webserver 14.1 Path Traversal via Directory Traversal Sequences
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-18T19:53:36.673Z

Updated: 2025-12-18T21:19:22.540Z

Reserved: 2025-12-16T19:22:09.998Z

Link: CVE-2023-53944

cve-icon Vulnrichment

Updated: 2025-12-18T20:18:10.327Z

cve-icon NVD

Status : Received

Published: 2025-12-18T20:15:53.097

Modified: 2025-12-18T22:15:54.863

Link: CVE-2023-53944

cve-icon Redhat

No data.