
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
An OS command injection vulnerability (CVE-2023-3767) was discovered in EasyPHP Webserver version 14.1. The vulnerability was discovered by security researcher Rafael Pedrero and was disclosed on September 27, 2023. EasyPHP is a popular web development environment that allows users to create and run PHP-based websites and applications on their local computers (Security Online, INCIBE Advisory).
The vulnerability is classified as an OS command injection (CWE-78) with a CVSS v3.1 base score of 9.8 (CRITICAL), and vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The vulnerability exists in the '/index.php?zone=settings' parameter, where an attacker can send specially crafted exploits to execute arbitrary commands on the affected system (NVD, INCIBE Advisory).
If successfully exploited, this vulnerability could allow an attacker to gain full access to the system, install malware, steal sensitive data, and disrupt or disable services (Security Online).
Users of EasyPHP Webserver version 14.1 are advised to upgrade to the latest version of the product which contains fixes for this vulnerability. If immediate upgrade is not possible, it is recommended to use a web application firewall (WAF) to filter out malicious requests and implement input validation to prevent attackers from injecting malicious code (Security Online).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”