Lucene search

K
cveMitreCVE-2021-34076
HistoryMay 11, 2023 - 12:15 p.m.

CVE-2021-34076

2023-05-1112:15:09
CWE-434
mitre
web.nvd.nist.gov
18
cve-2021-34076
file upload
phpok
remote attackers
arbitrary code
escalated privileges
zip file upload
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.002

Percentile

51.6%

File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload.

Affected configurations

Nvd
Node
phpokphpokMatch5.7.140
VendorProductVersionCPE
phpokphpok5.7.140cpe:2.3:a:phpok:phpok:5.7.140:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.002

Percentile

51.6%

Related for CVE-2021-34076