Phpkb

Vendor:

First CVE: Mar 12, 2020 · Active for 6 years

119
Total CVEs
More Total CVEs than 99% of tracked products
119.0
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
4.9
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Phpkb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 12, 2020
6 years ago
Most Recent CVE
Sep 3, 2020
2,152 days ago

CVE Severity & Scoring

Phpkb119 CVEs
All CVEs352,719 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network119 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low119 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (7.6%)
Unknown0 (0.0%)
Required110 (92.4%)
Privileges Required
Low1 (0.8%)
High89 (74.8%)
None29 (24.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (119 CVEs).

119 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php file in the admin/js/ directory.
Mar 12, 20207.233NOYES
An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclos
Sep 3, 20207.532NONO
Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via th
Mar 12, 20204.930NOYES
OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code
Mar 12, 20207.224NONO
CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potentially gaining code execution or causing a denial o
Mar 12, 20208.822NONO
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id, via a crafted request.
Mar 12, 20206.521NONO
Path Traversal in admin/imagepaster/operations.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete any folder on the webserver using a dot-dot-slash sequence (
Mar 12, 20206.520NONO
admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any POST parameter when saving global
Mar 12, 20207.220NONO
CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a crafted request.
Mar 12, 20204.318NONO
CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a crafted request.
Mar 12, 20204.318NONO

Exploit Exposure

Signals from CVEs in this product scope (119 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
1.7% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (119 CVEs).

Media Mentions

Signals from CVEs in this product scope (119 CVEs).

Top CNAs Publishing CVEs For Phpkb

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.01194.91.1%02