cve/2020/CVE-2020-16629.md
2024-05-25 21:48:12 +02:00

692 B

CVE-2020-16629

Description

PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path.

POC

Reference

No PoCs from references.

Github