EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root by bypassing SecurityManager restrictions. Attackers can send GET requests with encoded directory traversal sequences like /..%5c..%5c to read system files such as /windows/win.ini.
References
| Link | Resource |
|---|---|
| https://www.easyphp.org/ | Product |
| https://www.exploit-db.com/exploits/51430 | Exploit |
| https://www.vulncheck.com/advisories/easyphp-webserver-path-traversal-via-directory-traversal-sequences | Third Party Advisory Exploit |
| https://www.exploit-db.com/exploits/51430 | Exploit |
Configurations
History
26 Dec 2025, 16:55
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.easyphp.org/ - Product | |
| References | () https://www.exploit-db.com/exploits/51430 - Exploit | |
| References | () https://www.vulncheck.com/advisories/easyphp-webserver-path-traversal-via-directory-traversal-sequences - Third Party Advisory, Exploit | |
| CPE | cpe:2.3:a:easyphp:webserver:14.1:*:*:*:*:*:*:* | |
| First Time |
Easyphp
Easyphp webserver |
18 Dec 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/51430 - |
18 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-18 20:15
Updated : 2025-12-26 16:55
NVD link : CVE-2023-53944
Mitre link : CVE-2023-53944
CVE.ORG link : CVE-2023-53944
JSON object : View
Products Affected
easyphp
- webserver
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
