KingFor KFOX Arbitrary File Upload Vulnerability Allowing Web Shell Execution

Vulnerability

An arbitrary file upload vulnerability has been identified in KingFor KFOX versions through 2.6. This vulnerability allows remote attackers with regular privileges to upload and execute web shell backdoors, leading to arbitrary code execution on the server.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the server where KFOX is installed.

Remediation

Users are advised to contact KingFor customer service to arrange for the update and patching process.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.