PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-02-08T14:33:34

Updated: 2024-08-04T13:45:33.208Z

Reserved: 2020-08-04T00:00:00

Link: CVE-2020-16629

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-02-08T15:15:12.037

Modified: 2021-02-10T17:09:03.150

Link: CVE-2020-16629

cve-icon Redhat

No data.