Youphptube

Youphptube

18 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.44%
  • Published 01.11.2021 12:15:08
  • Last modified 21.11.2024 05:55:33

AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.

Exploit
  • EPSS 1.2%
  • Published 01.11.2021 12:15:08
  • Last modified 21.11.2024 05:55:33

AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.

Exploit
  • EPSS 0.44%
  • Published 01.11.2021 12:15:08
  • Last modified 21.11.2024 05:55:32

AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.

Exploit
  • EPSS 0.44%
  • Published 01.11.2021 12:15:08
  • Last modified 21.11.2024 05:55:32

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the searchPhrase parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administr...

Exploit
  • EPSS 0.83%
  • Published 01.11.2021 12:15:07
  • Last modified 21.11.2024 05:55:32

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.

  • EPSS 0.3%
  • Published 02.11.2019 15:15:10
  • Last modified 21.11.2024 04:33:28

An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being u...

Exploit
  • EPSS 0.37%
  • Published 31.10.2019 20:15:11
  • Last modified 21.11.2024 04:44:26

An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could ...

Exploit
  • EPSS 0.37%
  • Published 31.10.2019 20:15:11
  • Last modified 21.11.2024 04:44:26

An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. When the "VideoTags" plugin is enabled, a specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the databas...

Exploit
  • EPSS 0.3%
  • Published 25.10.2019 18:15:11
  • Last modified 21.11.2024 04:44:23

Specially crafted web requests can cause SQL injections in YouPHPTube 7.6. An attacker can send a web request with Parameter dir in /objects/pluginSwitch.json.php.

Exploit
  • EPSS 0.51%
  • Published 25.10.2019 18:15:11
  • Last modified 21.11.2024 04:44:23

SQL injection vulnerabilities exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with Parameter name in /objects/pluginSwitch.json.php.