Vulnerabilities > Phpok > Phpok > 4.9.032

DATE CVE VULNERABILITY TITLE RISK
2018-06-15 CVE-2018-12492 Improper Input Validation vulnerability in PHPok 4.9.032
PHPOK 4.9.032 has an arbitrary file deletion vulnerability in the delfile_f function in framework/admin/tpl_control.php.
network
low complexity
phpok CWE-20
6.4
2018-06-15 CVE-2018-12491 Unrestricted Upload of File with Dangerous Type vulnerability in PHPok 4.9.032
PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php file within a .php.zip archive, a similar issue to CVE-2018-8944.
network
low complexity
phpok CWE-434
7.5