Wwbn

Avideo

206 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 11.05.2026 20:32:05
  • Zuletzt bearbeitet 12.05.2026 14:50:18

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/MobileManager/oauth2.php completes an OAuth login by sending an HTTP 302 Location: oauth2Success.php?user=<email>&pass=<HASH> where <HASH> is the victim's stor...

  • EPSS 0.26%
  • Veröffentlicht 11.05.2026 20:31:06
  • Zuletzt bearbeitet 12.05.2026 14:50:18

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite/cloneClient.json.php echoes the local CloneSite shared secret ($objClone->myKey, a constant md5($global['systemRootPath'] . $global['salt'])) into th...

  • EPSS 0.24%
  • Veröffentlicht 11.05.2026 20:29:59
  • Zuletzt bearbeitet 12.05.2026 14:50:18

WWBN AVideo is an open source video platform. In versions up to and including 29.0, the server-side mitigation for the YPTSocket autoEvalCodeOnHTML eval sink (from CVE-2026-40911) only strips the payload when it sits under $json['msg'], but the relay...

Exploit
  • EPSS 2.22%
  • Veröffentlicht 21.04.2026 23:07:48
  • Zuletzt bearbeitet 24.04.2026 15:11:04

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is di...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 21.04.2026 23:04:32
  • Zuletzt bearbeitet 24.04.2026 15:10:50

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` for wget but leaves the `file_get_contents` and `curl` code paths unsanitized, and the URL validation ...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 21.04.2026 22:59:52
  • Zuletzt bearbeitet 24.04.2026 15:08:58

WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides `inlineMarkup` for raw HTML but does not override `inlineLink()` or `inlineUrlTag()`, allowing `javas...

Exploit
  • EPSS 0.72%
  • Veröffentlicht 21.04.2026 22:57:26
  • Zuletzt bearbeitet 24.04.2026 15:08:46

WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in commit 2375eb5e0 for `objects/aVideoEncoderReceiveImage.json.php` only checks the URL path component (via `parse_url($url, PHP_URL_PAT...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 21.04.2026 22:49:40
  • Zuletzt bearbeitet 24.04.2026 15:08:34

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/video.php:918` uses `/^[0-9]{1,2}:[0-9]{1,2}:[0-9]{1,2}/` without a `$` end anchor, allowing arbitrary HTML/JavaScript to be appended ...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 21.04.2026 22:44:44
  • Zuletzt bearbeitet 24.04.2026 15:08:25

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/functions.php` contains a same-domain shortcircuit (lines 4290-4296) that allows any URL whose hostname matches `webSiteRootURL` to b...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 21.04.2026 22:43:17
  • Zuletzt bearbeitet 24.04.2026 15:07:57

WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not apply path traversal filtering, allowing `unlink()` of arbitrary files via `../../` sequences in the G...