Wwbn

Avideo

55 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.33%
  • Veröffentlicht 10.01.2024 16:15:49
  • Zuletzt bearbeitet 21.11.2024 08:33:58

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is tr...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 10.01.2024 16:15:49
  • Zuletzt bearbeitet 21.11.2024 08:33:57

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is tr...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 10.01.2024 16:15:48
  • Zuletzt bearbeitet 21.11.2024 08:33:53

A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to captcha bypass, which can be abused by an attacker to brute forc...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 10.01.2024 16:15:48
  • Zuletzt bearbeitet 21.11.2024 08:33:36

An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker ca...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 10.01.2024 16:15:48
  • Zuletzt bearbeitet 21.11.2024 08:33:37

An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via...

Exploit
  • EPSS 0.51%
  • Veröffentlicht 10.01.2024 16:15:48
  • Zuletzt bearbeitet 21.11.2024 08:33:44

A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution when chained with an LFI vulner...

Exploit
  • EPSS 0.78%
  • Veröffentlicht 10.01.2024 16:15:48
  • Zuletzt bearbeitet 21.11.2024 08:33:45

An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.

Exploit
  • EPSS 0.33%
  • Veröffentlicht 10.01.2024 16:15:48
  • Zuletzt bearbeitet 21.11.2024 08:33:57

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is tr...

  • EPSS 0.35%
  • Veröffentlicht 10.01.2024 16:15:47
  • Zuletzt bearbeitet 21.11.2024 08:32:20

A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a use...

Exploit
  • EPSS 21.89%
  • Veröffentlicht 10.01.2024 16:15:47
  • Zuletzt bearbeitet 21.11.2024 08:32:20

A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get...