phpok records
23 published records for vendor phpok.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-502 Deserialization of Untrusted Data2
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-18440No exploit | Buffer overflow vulnerability in framework/init.php in qinggan phpok 5.1, allows attackers to execute arbitrary code.phpok · phpok · CWE-120 | Critical9.8 | — | 1.7% | Nov 2, 2021 |
39Monitor | CVE-2018-12491No exploit | PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated byphpok · phpok · CWE-434 | Critical9.8 | — | 1.7% | Jun 15, 2018 |
39Monitor | CVE-2020-16629No exploit | PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacemenphpok · phpok · CWE-89 | Critical9.8 | — | 1.4% | Feb 8, 2021 |
39Monitor | CVE-2022-29363No exploit | Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php.phpok · phpok · CWE-502 | Critical9.8 | — | 1.3% | May 12, 2022 |
39Monitor | CVE-2022-47129No exploit | PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.phpok · phpok · CWE-94 | Critical9.8 | — | 1.2% | May 11, 2023 |
39Monitor | CVE-2018-8944No exploit | PHPOK 4.8.338 has an arbitrary file upload vulnerability.phpok · phpok · CWE-434 | Critical9.8 | — | 1.2% | Mar 22, 2018 |
39Monitor | CVE-2022-40889No exploit | Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.phpok · phpok · CWE-502 | Critical9.8 | — | 1.1% | Oct 18, 2022 |
37Monitor | CVE-2019-16131No exploit | framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file from a ZIP archive can phpok · oklite · CWE-434 | High8.8 | — | 6.5% | Sep 8, 2019 |
36Monitor | CVE-2018-19562No exploit | An issue was discovered in PHPok 4.9.015.phpok · phpok · CWE-434 | High8.8 | — | 2.2% | Nov 26, 2018 |
36Monitor | CVE-2020-18439No exploit | An issue was discoverered in in function edit_save_f in framework/admin/tpl_control.php in qinggan phpok 5.1, allows attackers to write arbiphpok · phpok | Critical9.1 | — | 1.0% | Nov 2, 2021 |
35Monitor | CVE-2023-33601No exploit | An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary code via a crafted PHPphpok · phpok · CWE-434 | High8.8 | — | 0.9% | Jun 6, 2023 |
35Monitor | CVE-2020-19199No exploit | A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious uphpok · phpok · CWE-352 | High8.8 | — | 0.9% | May 10, 2021 |
35Monitor | CVE-2021-34076No exploit | File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file phpok · phpok · CWE-434 | High8.8 | — | 0.9% | May 11, 2023 |
35Monitor | CVE-2023-2888No exploit | PHPOK unrestricted uploadphpok · phpok · CWE-434 | High8.8 | — | 0.7% | May 25, 2023 |
30Monitor | CVE-2020-18438No exploit | Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the title parameter to adminphpok · phpok · CWE-22 | High7.5 | — | 1.7% | Nov 2, 2021 |
30Monitor | CVE-2024-44867Proof of concept | phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.phpok · phpok · CWE-22 | High7.5 | — | 1.0% | Sep 10, 2024 |
30Monitor | CVE-2018-12492No exploit | PHPOK 4.9.032 has an arbitrary file deletion vulnerability in the delfile_f function in framework/admin/tpl_control.php.phpok · phpok · CWE-20 | High7.5 | — | 0.9% | Jun 15, 2018 |
30Monitor | CVE-2020-21486No exploit | SQL injection vulnerability in PHPOK v.5.4.phpok · phpok · CWE-89 | High7.5 | — | 0.9% | Jun 20, 2023 |
28Monitor | CVE-2019-16132No exploit | An issue was discovered in OKLite v1.2.25.phpok · oklite · CWE-22 | Medium6.5 | — | 6.1% | Sep 8, 2019 |
26Monitor | CVE-2023-29881No exploit | phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php.phpok · phpok · CWE-89 | Medium6.5 | — | 0.4% | May 14, 2024 |
24Monitor | CVE-2018-16142No exploit | PHPOK 4.8.278 has a Reflected XSS vulnerability in framework/www/login_control.php via the _back parameter to the ok_f function.phpok · phpok · CWE-79 | Medium6.1 | — | 0.7% | Aug 30, 2018 |
24Monitor | CVE-2018-20006No exploit | An issue was discovered in PHPok v5.0.055.phpok · phpok · CWE-79 | Medium6.1 | — | 0.6% | Dec 10, 2018 |
24Monitor | CVE-2024-38953No exploit | phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file.phpok · phpok · CWE-79 | Medium6.1 | — | 0.3% | Jul 1, 2024 |
- CVE-2020-1844039Monitor
Buffer overflow vulnerability in framework/init.php in qinggan phpok 5.1, allows attackers to execute arbitrary code.
CriticalCVSS 9.8No exploitEPSS 2%phpok · phpokNov 2, 2021
- CVE-2018-1249139Monitor
PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by
CriticalCVSS 9.8No exploitEPSS 2%phpok · phpokJun 15, 2018
- CVE-2020-1662939Monitor
PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacemen
CriticalCVSS 9.8No exploitEPSS 1%phpok · phpokFeb 8, 2021
- CVE-2022-2936339Monitor
Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php.
CriticalCVSS 9.8No exploitEPSS 1%phpok · phpokMay 12, 2022
- CVE-2022-4712939Monitor
PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%phpok · phpokMay 11, 2023
- CVE-2018-894439Monitor
PHPOK 4.8.338 has an arbitrary file upload vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%phpok · phpokMar 22, 2018
- CVE-2022-4088939Monitor
Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.
CriticalCVSS 9.8No exploitEPSS 1%phpok · phpokOct 18, 2022
- CVE-2019-1613137Monitor
framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file from a ZIP archive can
HighCVSS 8.8No exploitEPSS 7%phpok · okliteSep 8, 2019
- CVE-2018-1956236Monitor
An issue was discovered in PHPok 4.9.015.
HighCVSS 8.8No exploitEPSS 2%phpok · phpokNov 26, 2018
- CVE-2020-1843936Monitor
An issue was discoverered in in function edit_save_f in framework/admin/tpl_control.php in qinggan phpok 5.1, allows attackers to write arbi
CriticalCVSS 9.1No exploitEPSS 1%phpok · phpokNov 2, 2021
- CVE-2023-3360135Monitor
An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary code via a crafted PHP
HighCVSS 8.8No exploitEPSS 1%phpok · phpokJun 6, 2023
- CVE-2020-1919935Monitor
A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious u
HighCVSS 8.8No exploitEPSS 1%phpok · phpokMay 10, 2021
- CVE-2021-3407635Monitor
File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file
HighCVSS 8.8No exploitEPSS 1%phpok · phpokMay 11, 2023
- CVE-2023-288835Monitor
PHPOK unrestricted upload
HighCVSS 8.8No exploitEPSS 1%phpok · phpokMay 25, 2023
- CVE-2020-1843830Monitor
Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the title parameter to admin
HighCVSS 7.5No exploitEPSS 2%phpok · phpokNov 2, 2021
- CVE-2024-4486730Monitor
phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.
HighCVSS 7.5Proof of conceptEPSS 1%phpok · phpokSep 10, 2024
- CVE-2018-1249230Monitor
PHPOK 4.9.032 has an arbitrary file deletion vulnerability in the delfile_f function in framework/admin/tpl_control.php.
HighCVSS 7.5No exploitEPSS 1%phpok · phpokJun 15, 2018
- CVE-2020-2148630Monitor
SQL injection vulnerability in PHPOK v.5.4.
HighCVSS 7.5No exploitEPSS 1%phpok · phpokJun 20, 2023
- CVE-2019-1613228Monitor
An issue was discovered in OKLite v1.2.25.
MediumCVSS 6.5No exploitEPSS 6%phpok · okliteSep 8, 2019
- CVE-2023-2988126Monitor
phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php.
MediumCVSS 6.5No exploitEPSS 0%phpok · phpokMay 14, 2024
- CVE-2018-1614224Monitor
PHPOK 4.8.278 has a Reflected XSS vulnerability in framework/www/login_control.php via the _back parameter to the ok_f function.
MediumCVSS 6.1No exploitEPSS 1%phpok · phpokAug 30, 2018
- CVE-2018-2000624Monitor
An issue was discovered in PHPok v5.0.055.
MediumCVSS 6.1No exploitEPSS 1%phpok · phpokDec 10, 2018
- CVE-2024-3895324Monitor
phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file.
MediumCVSS 6.1No exploitEPSS 0%phpok · phpokJul 1, 2024