ZeroHour

Vulnerabilities

23 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-44867
phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.

phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.

NVD description · AI analysis pending
7.51% PoC
  • phpok phpok
CVE-2024-38953
phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file.

phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file.

NVD description · AI analysis pending
6.1<1% PoC
  • phpok phpok
CVE-2023-29881
phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php.

phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php.

NVD description · AI analysis pending
6.5<1% PoC
  • phpok phpok
CVE-2020-21486
SQL injection vulnerability in PHPOK v.5.4.

SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file.

NVD description · AI analysis pending
7.5<1% PoC
  • phpok phpok
CVE-2023-33601
An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary code via a crafted PHP file.

An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary code via a crafted PHP file.

NVD description · AI analysis pending
8.8<1% PoC
  • phpok phpok
CVE-2023-2888
A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100.

A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&_noCache=0.1683794968. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The identifier VDB-229953 was assigned to this vulnerability.

NVD description · AI analysis pending
8.8<1% PoC
  • phpok phpok
CVE-2022-47129
+1 in the same advisory: …34076
PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.

PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.

NVD description · AI analysis pending
9.8
group max
1%
  • phpok phpok
CVE-2022-40889
Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.

Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.

NVD description · AI analysis pending
9.81% PoC
  • phpok phpok
CVE-2022-29363
Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php.

Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files.

NVD description · AI analysis pending
9.81% PoC
  • phpok phpok
CVE-2020-18440
+2 in the same advisory: …18439 …18438
Buffer overflow vulnerability in framework/init.php in qinggan phpok 5.1, allows attackers to execute arbitrary code.

Buffer overflow vulnerability in framework/init.php in qinggan phpok 5.1, allows attackers to execute arbitrary code.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • phpok phpok
CVE-2020-19199
A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious user execute arbitrar

A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious user execute arbitrary code.

NVD description · AI analysis pending
8.8<1% PoC
  • phpok phpok
CVE-2020-16629
PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through a

PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path.

NVD description · AI analysis pending
9.81% PoC
  • phpok phpok
CVE-2019-16131
+1 in the same advisory: …16132
framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file from a ZIP archive can be written to /data/

framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file from a ZIP archive can be written to /data/cache/.

NVD description · AI analysis pending
8.8
group max
7% PoC
  • phpok oklite
CVE-2018-20006
An issue was discovered in PHPok v5.0.055.

An issue was discovered in PHPok v5.0.055. There is a Stored XSS vulnerability via the title parameter to api.php?c=post&f=save (reachable via the index.php?id=book URI).

NVD description · AI analysis pending
6.1<1% PoC
  • phpok phpok
CVE-2018-19562
An issue was discovered in PHPok 4.9.015.

An issue was discovered in PHPok 4.9.015. admin.php?c=update&f=unzip allows remote attackers to execute arbitrary code via a "Login Background > Program Upgrade > Compressed Packet Upgrade" action in which a .php file is inside a ZIP archive.

NVD description · AI analysis pending
8.82% PoC
  • phpok phpok
CVE-2018-16142
PHPOK 4.8.278 has a Reflected XSS vulnerability in framework/www/login_control.php via the _back parameter to the ok_f function.

PHPOK 4.8.278 has a Reflected XSS vulnerability in framework/www/login_control.php via the _back parameter to the ok_f function.

NVD description · AI analysis pending
6.1<1% PoC
  • phpok phpok
CVE-2018-12491
+1 in the same advisory: …12492
PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php fi

PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php file within a .php.zip archive, a similar issue to CVE-2018-8944.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • phpok phpok
CVE-2018-8944
PHPOK 4.8.338 has an arbitrary file upload vulnerability.

PHPOK 4.8.338 has an arbitrary file upload vulnerability.

NVD description · AI analysis pending
9.81%
  • phpok phpok