Description
PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-8590 | PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path. |
References
| Link | Providers |
|---|---|
| https://github.com/Gh0stF/phpok_cve/issues/1 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T13:45:33.208Z
Reserved: 2020-08-04T00:00:00.000Z
Link: CVE-2020-16629
No data.
Status : Modified
Published: 2021-02-08T15:15:12.037
Modified: 2024-11-21T05:07:11.693
Link: CVE-2020-16629
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD