7.5
CVSSv3

CVE-2020-11579

Published: 03/09/2020 Updated: 03/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated malicious user to disclose local files on hosts running PHP prior to 7.2.16, or on hosts where the MySQL ALLOW LOCAL DATA INFILE option is enabled.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

chadhaajay phpkb 9.0

Github Repositories

Exploit code for CVE-2020-11579, an arbitrary file disclosure through the MySQL client in PHPKB

CVE-2020-11579 Introduction PHPKB 90 Enterprise Edition (MySQL database) is affected by an unauthenticated arbitrary file disclosure via a malicious MySQL Server A remote attacker can read any file on a remote victim host with web-server privileges (eg www-data), via a single HTTP GET request Read more at shielderit/blog/mysql-and-cve-2020-11579-exploitation Note