Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. This vulnerability could allow remote users to bypass SecurityManager restrictions and retrieve any file stored on the server by setting only consecutive strings ‘/...%5c’.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 14 Nov 2024 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. This vulnerability could allow remote users to bypass SecurityManager restrictions and retrieve any file stored on the server by setting only consecutive strings ‘/...%5c’. | |
Title | Path traversal vulnerability in EasyPHP | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: INCIBE
Published: 2024-11-14T13:37:04.665Z
Updated: 2024-11-14T14:27:02.624Z
Reserved: 2024-11-14T08:26:53.402Z
Link: CVE-2024-11215

Updated: 2024-11-14T14:25:31.517Z

Status : Awaiting Analysis
Published: 2024-11-14T14:15:18.367
Modified: 2024-11-15T13:58:08.913
Link: CVE-2024-11215

No data.