CVE-2023-53941
EUVD-2025-20434118.12.2025, 20:15
EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by injecting malicious payloads through the app_service_control parameter. Attackers can send POST requests to /index.php?zone=settings with crafted app_service_control values to execute commands with administrative privileges.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| easyphp | webserver | 14.1 |
𝑥
= Vulnerable software versions