vendor:
PHPKB Multi-Language 9
by:
Antonio Cannito
7.2
CVSS
HIGH
Remote Code Execution
CWE
Product Name: PHPKB Multi-Language 9
Affected Version From: Multi-Language v9
Affected Version To: Multi-Language v9
Patch Exists: NO
Related CWE: CVE-2020-10386
CPE:
Platforms Tested: Windows 8.1 / PHP 7.4.3
2020
PHPKB Multi-Language 9 – ‘image-upload.php’ Authenticated Remote Code Execution
This exploit allows an authenticated user to execute arbitrary commands on the target system by uploading a specially crafted PHP file. The vulnerability exists in the 'image-upload.php' file of PHPKB Multi-Language 9. By uploading a PHP file containing the desired command, the attacker can execute it by visiting the generated URL.
Mitigation:
Apply the vendor's patch or update to a version that has this vulnerability fixed. Additionally, restrict access to the 'image-upload.php' file and ensure that only trusted users have access to it.