6.5
CVSSv2

CVE-2020-10386

Published: 12/03/2020 Updated: 18/04/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote malicious users to achieve Code Execution by uploading a .php file in the admin/js/ directory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

chadhaajay phpkb 9.0

Exploits

# Exploit Title: PHPKB Multi-Language 9 - 'image-uploadphp' Authenticated Remote Code Execution # Google Dork: N/A # Date: 2020-03-15 # Exploit Author: Antonio Cannito # Vendor Homepage: wwwknowledgebase-scriptcom/ # Software Link: wwwknowledgebase-scriptcom/pricingphp # Version: Multi-Language v9 # Tested on: Windows 81 / PH ...
PHPKB Multi-Language 9 suffers from an image-uploadphp remote authenticated code execution vulnerability ...