Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-43865
HistoryMay 29, 2023 - 12:00 a.m.

PHPOK Arbitrary File Upload Vulnerability (CNVD-2023-43865)

2023-05-2900:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
phpok
arbitrary file upload
vulnerability
version 6.4.100
remote code execution
admin.php
upload validation

EPSS

0.001

Percentile

50.5%

PHPOK is an enterprise building system that supports expansion. PHPOK version 6.4.100 suffers from an arbitrary file upload vulnerability, which stems from admin.php?c=upload&f=zip&_noCache=0.1683794968 lack of valid validation of the uploaded file. An attacker can exploit this vulnerability to upload malicious files and remotely execute arbitrary code.

EPSS

0.001

Percentile

50.5%

Related for CNVD-2023-43865