PT-2026-3030 · Phpkf Cms · Phpkf Cms

Halit Akaydin

·

Publicado

2026-01-15

·

Atualizado

2026-01-20

·

CVE-2021-47753

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpKF CMS version 3.00 Beta y6
Description The software contains an unauthenticated file upload issue that enables remote attackers to execute arbitrary code. This is achieved by bypassing file extension checks, allowing attackers to upload a PHP file disguised as a PNG. After uploading, the file can be renamed and used to execute system commands through a crafted web shell parameter.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2021-47753

Produtos afetados

Phpkf Cms