Vulnerabilities (CVE)

Filtered by vendor Phpok Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-29363 1 Phpok 1 Phpok 2022-05-23 7.5 HIGH 9.8 CRITICAL
Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files.
CVE-2020-18440 1 Phpok 1 Phpok 2021-11-03 7.5 HIGH 9.8 CRITICAL
Buffer overflow vulnerability in framework/init.php in qinggan phpok 5.1, allows attackers to execute arbitrary code.
CVE-2020-18439 1 Phpok 1 Phpok 2021-11-03 6.4 MEDIUM 9.1 CRITICAL
An issue was discoverered in in function edit_save_f in framework/admin/tpl_control.php in qinggan phpok 5.1, allows attackers to write arbitrary files or get a shell.
CVE-2020-16629 1 Phpok 1 Phpok 2021-02-10 7.5 HIGH 9.8 CRITICAL
PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path.
CVE-2018-12491 1 Phpok 1 Phpok 2018-07-27 7.5 HIGH 9.8 CRITICAL
PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php file within a .php.zip archive, a similar issue to CVE-2018-8944.
CVE-2018-8944 1 Phpok 1 Phpok 2018-04-20 7.5 HIGH 9.8 CRITICAL
PHPOK 4.8.338 has an arbitrary file upload vulnerability.