6.5
CVSSv3

CVE-2024-11215

CVSSv4: NA | CVSSv3: 6.5 | CVSSv2: NA | VMScore: 750 | EPSS: 0.00086 | KEV: Not Included
Published: 14/11/2024 Updated: 15/11/2024

Vulnerability Summary

Absolute Path Traversal Vulnerability in EasyPHP 14.1 Exploited

There is a vulnerability in EasyPHP web server version 14.1. This is an absolute path traversal issue. It means the server does not correctly keep file paths inside a restricted directory. Remote users can use this vulnerability. They can bypass SecurityManager restrictions. By setting strings '...%5c', they can get any file from the server.