4
CVSSv2

CVE-2020-10387

Published: 12/03/2020 Updated: 19/08/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote malicious users to download files from the server using a dot-dot-slash sequence (../) via the GET parameter file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

chadhaajay phpkb 9.0

Exploits

# Exploit Title: PHPKB Multi-Language 9 - Authenticated Directory Traversal # Google Dork: N/A # Date: 2020-03-15 # Exploit Author: Antonio Cannito # Vendor Homepage: wwwknowledgebase-scriptcom/ # Software Link: wwwknowledgebase-scriptcom/pricingphp # Version: Multi-Language v9 # Tested on: Windows 81 / PHP 743 # CVE : CVE-2 ...
PHPKB Multi-Language 9 suffers from an authenticated directory traversal vulnerability ...