EasyPHP - '/index.php' Authentication Bypass / Remote PHP Code Injection

EDB-ID:

38438

CVE:

N/A


Platform:

PHP

Published:

2013-04-09

source: http://www.securityfocus.com/bid/58945/info

EasyPHP is prone to an authentication bypass and a PHP code execution vulnerability.

Attackers may exploit these issues to gain unauthorized access to the affected application and perform arbitrary actions or execute arbitrary PHP code within the context of the web server process. Successful attacks can compromise the affected application and possibly the underlying computer.

EasyPHP 12.1 is vulnerable; other versions may also be affected. 

http://www.example.com/home/index.php?to=ext

http://www.example.com/home/index.php?to=phpinfo