Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2024-11215

Disclosure Date: November 14, 2024 (last updated November 15, 2024)
Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. This vulnerability could allow remote users to bypass SecurityManager restrictions and retrieve any file stored on the server by setting only consecutive strings ‘/...%5c’.
0
Attacker Value
Unknown

CVE-2023-3767

Disclosure Date: September 27, 2023 (last updated October 08, 2023)
An OS command injection vulnerability has been found on EasyPHP Webserver affecting version 14.1. This vulnerability could allow an attacker to get full access to the system by sending a specially crafted exploit to the /index.php?zone=settings parameter.
Attacker Value
Unknown

CVE-2005-2155

Disclosure Date: July 06, 2005 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.
0
Attacker Value
Unknown

CVE-2005-1144

Disclosure Date: April 12, 2005 (last updated February 22, 2025)
popup.php in EasyPHPCalendar before 6.2.8 allows remote attackers to obtain sensitive information via an invalid ev parameter, which reveals the full pathname of the web server in a PHP error message.
0
Attacker Value
Unknown

CVE-2005-1143

Disclosure Date: April 12, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php in EasyPHPCalendar before 6.2.8 allows remote attackers to inject arbitrary web script or HTML via the yr parameter.
0