Wwbn

Avideo

220 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.32%
  • Veröffentlicht 10.01.2024 16:15:48
  • Zuletzt bearbeitet 04.11.2025 19:16:09

An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.

Exploit
  • EPSS 0.67%
  • Veröffentlicht 10.01.2024 16:15:48
  • Zuletzt bearbeitet 04.11.2025 19:16:09

A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to captcha bypass, which can be abused by an attacker to brute forc...

Exploit
  • EPSS 1.07%
  • Veröffentlicht 10.01.2024 16:15:48
  • Zuletzt bearbeitet 04.11.2025 19:16:10

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is tr...

Exploit
  • EPSS 1.07%
  • Veröffentlicht 10.01.2024 16:15:47
  • Zuletzt bearbeitet 04.11.2025 19:16:05

An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.

Exploit
  • EPSS 0.8%
  • Veröffentlicht 10.01.2024 16:15:47
  • Zuletzt bearbeitet 04.11.2025 19:16:06

A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a ...

  • EPSS 1.07%
  • Veröffentlicht 10.01.2024 16:15:47
  • Zuletzt bearbeitet 04.11.2025 19:16:06

A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send a series of HTTP requests...

Exploit
  • EPSS 2.27%
  • Veröffentlicht 10.01.2024 16:15:47
  • Zuletzt bearbeitet 04.11.2025 19:16:07

A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get...

  • EPSS 0.58%
  • Veröffentlicht 10.01.2024 16:15:47
  • Zuletzt bearbeitet 04.11.2025 19:16:07

A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a use...

Exploit
  • EPSS 6.46%
  • Veröffentlicht 12.05.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 08:02:39

WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `plugin/CloneSite/cloneClient.json.php` which allows Remote Code Execution if you CloneSite Plugin. This is a bypass to the fix for ...

Exploit
  • EPSS 0.71%
  • Veröffentlicht 08.05.2023 19:15:12
  • Zuletzt bearbeitet 21.11.2024 08:00:59

WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can make a Meeting Schedule where the user can invite another user in that Meeting, but it does not properly sanitize the malicious characters when creating ...