CVE-2024-44867
- EPSS 19.27%
- Veröffentlicht 10.09.2024 14:15:13
- Zuletzt bearbeitet 10.07.2025 15:25:49
phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.
CVE-2024-38953
- EPSS 0.16%
- Veröffentlicht 01.07.2024 14:15:05
- Zuletzt bearbeitet 20.03.2025 21:15:20
phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file.
CVE-2023-29881
- EPSS 0.13%
- Veröffentlicht 14.05.2024 12:55:53
- Zuletzt bearbeitet 13.06.2025 12:59:14
phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php.
CVE-2020-21486
- EPSS 0.04%
- Veröffentlicht 20.06.2023 15:15:11
- Zuletzt bearbeitet 09.12.2024 22:15:21
SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file.
CVE-2023-33601
- EPSS 0.17%
- Veröffentlicht 07.06.2023 02:15:15
- Zuletzt bearbeitet 07.01.2025 15:15:08
An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2023-2888
- EPSS 0.08%
- Veröffentlicht 25.05.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:30
A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&_noCache=0.1683794968. The manipulation leads to unrestricted upload. It is possible to initiate the ...
CVE-2022-47129
- EPSS 2.84%
- Veröffentlicht 11.05.2023 14:15:19
- Zuletzt bearbeitet 27.01.2025 17:15:09
PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.
CVE-2021-34076
- EPSS 0.29%
- Veröffentlicht 11.05.2023 12:15:09
- Zuletzt bearbeitet 27.01.2025 17:15:08
File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload.
CVE-2022-40889
- EPSS 0.26%
- Veröffentlicht 18.10.2022 11:15:10
- Zuletzt bearbeitet 13.05.2025 15:15:49
Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.
CVE-2022-29363
- EPSS 0.2%
- Veröffentlicht 12.05.2022 18:16:53
- Zuletzt bearbeitet 21.11.2024 06:58:58
Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files.