Phpok
by Phpok
CVEs (22)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-47129 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2023 | PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability. | ||
| CVE-2022-40889 | Cri | 0.64 | 9.8 | 0.01 | Oct 18, 2022 | Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php. | ||
| CVE-2022-29363 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files. | ||
| CVE-2020-18440 | Cri | 0.64 | 9.8 | 0.02 | Nov 2, 2021 | Buffer overflow vulnerability in framework/init.php in qinggan phpok 5.1, allows attackers to execute arbitrary code. | ||
| CVE-2020-16629 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2021 | PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path. | ||
| CVE-2018-12491 | Cri | 0.64 | 9.8 | 0.02 | Jun 15, 2018 | PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php file within a .php.zip archive, a similar issue to CVE-2018-8944. | ||
| CVE-2018-8944 | Cri | 0.64 | 9.8 | 0.01 | Mar 22, 2018 | PHPOK 4.8.338 has an arbitrary file upload vulnerability. | ||
| CVE-2020-18439 | Cri | 0.59 | 9.1 | 0.01 | Nov 2, 2021 | An issue was discoverered in in function edit_save_f in framework/admin/tpl_control.php in qinggan phpok 5.1, allows attackers to write arbitrary files or get a shell. | ||
| CVE-2023-33601 | Hig | 0.57 | 8.8 | 0.01 | Jun 7, 2023 | An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2021-34076 | Hig | 0.57 | 8.8 | 0.01 | May 11, 2023 | File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload. | ||
| CVE-2020-19199 | Hig | 0.57 | 8.8 | 0.01 | May 10, 2021 | A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious user execute arbitrary code. | ||
| CVE-2018-19562 | Hig | 0.57 | 8.8 | 0.02 | Nov 26, 2018 | An issue was discovered in PHPok 4.9.015. admin.php?c=update&f=unzip allows remote attackers to execute arbitrary code via a "Login Background > Program Upgrade > Compressed Packet Upgrade" action in which a .php file is inside a ZIP archive. | ||
| CVE-2024-44867 | Hig | 0.49 | 7.5 | 0.01 | Sep 10, 2024 | phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php. | ||
| CVE-2020-21486 | Hig | 0.49 | 7.5 | 0.01 | Jun 20, 2023 | SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file. | ||
| CVE-2020-18438 | Hig | 0.49 | 7.5 | 0.02 | Nov 2, 2021 | Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the title parameter to admin.php. | ||
| CVE-2018-12492 | Hig | 0.49 | 7.5 | 0.01 | Jun 15, 2018 | PHPOK 4.9.032 has an arbitrary file deletion vulnerability in the delfile_f function in framework/admin/tpl_control.php. | ||
| CVE-2025-15142 | Hig | 0.47 | 7.3 | 0.00 | Dec 28, 2025 | A vulnerability was identified in 9786 phpok3w up to 901d96a06809fb28b17f3a4362c59e70411c933c. Impacted is an unknown function of the file show.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is… | ||
| CVE-2023-29881 | Med | 0.42 | 6.5 | 0.00 | May 14, 2024 | phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php. | ||
| CVE-2024-38953 | Med | 0.40 | 6.1 | 0.00 | Jul 1, 2024 | phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file. | ||
| CVE-2018-20006 | Med | 0.40 | 6.1 | 0.01 | Dec 10, 2018 | An issue was discovered in PHPok v5.0.055. There is a Stored XSS vulnerability via the title parameter to api.php?c=post&f=save (reachable via the index.php?id=book URI). |
- risk 0.64cvss 9.8epss 0.01
PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.
- risk 0.64cvss 9.8epss 0.01
Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.
- risk 0.64cvss 9.8epss 0.01
Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files.
- risk 0.64cvss 9.8epss 0.02
Buffer overflow vulnerability in framework/init.php in qinggan phpok 5.1, allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path.
- risk 0.64cvss 9.8epss 0.02
PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php file within a .php.zip archive, a similar issue to CVE-2018-8944.
- risk 0.64cvss 9.8epss 0.01
PHPOK 4.8.338 has an arbitrary file upload vulnerability.
- risk 0.59cvss 9.1epss 0.01
An issue was discoverered in in function edit_save_f in framework/admin/tpl_control.php in qinggan phpok 5.1, allows attackers to write arbitrary files or get a shell.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.57cvss 8.8epss 0.01
File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload.
- risk 0.57cvss 8.8epss 0.01
A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious user execute arbitrary code.
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in PHPok 4.9.015. admin.php?c=update&f=unzip allows remote attackers to execute arbitrary code via a "Login Background > Program Upgrade > Compressed Packet Upgrade" action in which a .php file is inside a ZIP archive.
- risk 0.49cvss 7.5epss 0.01
phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.
- risk 0.49cvss 7.5epss 0.01
SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file.
- risk 0.49cvss 7.5epss 0.02
Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the title parameter to admin.php.
- risk 0.49cvss 7.5epss 0.01
PHPOK 4.9.032 has an arbitrary file deletion vulnerability in the delfile_f function in framework/admin/tpl_control.php.
- risk 0.47cvss 7.3epss 0.00
A vulnerability was identified in 9786 phpok3w up to 901d96a06809fb28b17f3a4362c59e70411c933c. Impacted is an unknown function of the file show.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is…
- risk 0.42cvss 6.5epss 0.00
phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php.
- risk 0.40cvss 6.1epss 0.00
phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in PHPok v5.0.055. There is a Stored XSS vulnerability via the title parameter to api.php?c=post&f=save (reachable via the index.php?id=book URI).
Page 1 of 2