Wwbn

Avideo

55 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.14%
  • Veröffentlicht 24.07.2025 15:11:06
  • Zuletzt bearbeitet 03.11.2025 20:19:05

A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 24.07.2025 15:11:04
  • Zuletzt bearbeitet 03.11.2025 20:19:13

A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a us...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 24.07.2025 15:11:03
  • Zuletzt bearbeitet 03.11.2025 20:19:12

A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker ca...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 24.07.2025 15:11:01
  • Zuletzt bearbeitet 03.11.2025 20:18:30

A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An at...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 24.07.2025 15:11:00
  • Zuletzt bearbeitet 03.11.2025 20:18:48

A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get ...

Exploit
  • EPSS 0.82%
  • Veröffentlicht 24.07.2025 15:10:58
  • Zuletzt bearbeitet 03.11.2025 20:17:57

A race condition vulnerability exists in the aVideoEncoder.json.php unzip functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A series of specially crafted HTTP request can lead to arbitrary code execution.

Exploit
  • EPSS 1.76%
  • Veröffentlicht 24.07.2025 15:10:56
  • Zuletzt bearbeitet 03.11.2025 20:19:07

An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can request a .phar file to trigger this vulnerability.

Exploit
  • EPSS 0.12%
  • Veröffentlicht 14.05.2024 15:39:37
  • Zuletzt bearbeitet 18.06.2025 17:41:45

WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).

Exploit
  • EPSS 80.42%
  • Veröffentlicht 10.04.2024 20:15:08
  • Zuletzt bearbeitet 17.06.2025 20:56:26

An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 10.01.2024 16:15:49
  • Zuletzt bearbeitet 04.11.2025 19:16:14

A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to the silent creation of a recovery pass code for ...