PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php file within a .php.zip archive, a similar issue to CVE-2018-8944.
References
Link | Resource |
---|---|
https://github.com/SukaraLin/php_code_audit_project/blob/master/phpok/Phpok%204.9.032%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1.md | Exploit Third Party Advisory |
Configurations
Information
Published : 2018-06-15 11:29
Updated : 2018-07-27 07:04
NVD link : CVE-2018-12491
Mitre link : CVE-2018-12491
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
phpok
- phpok