phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file extension checks. Attackers can upload a PHP file disguised as a PNG, rename it, and execute system commands through a crafted web shell parameter.
Metrics
Affected Vendors & Products
References
History
Thu, 15 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 15 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file extension checks. Attackers can upload a PHP file disguised as a PNG, rename it, and execute system commands through a crafted web shell parameter. | |
| Title | phpKF CMS 3.00 Beta y6 - Remote Code Execution (RCE) (Unauthenticated) | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-15T18:27:25.683Z
Reserved: 2026-01-10T13:48:08.268Z
Link: CVE-2021-47753
Updated: 2026-01-15T16:13:53.666Z
Status : Received
Published: 2026-01-15T16:16:06.003
Modified: 2026-01-15T19:16:01.530
Link: CVE-2021-47753
No data.
OpenCVE Enrichment
No data.