CVE-2021-25878
- EPSS 0.44%
- Published 01.11.2021 12:15:08
- Last modified 21.11.2024 05:55:33
AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.
- EPSS 1.2%
- Published 01.11.2021 12:15:08
- Last modified 21.11.2024 05:55:33
AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.
CVE-2021-25876
- EPSS 0.44%
- Published 01.11.2021 12:15:08
- Last modified 21.11.2024 05:55:32
AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.
CVE-2021-25875
- EPSS 0.44%
- Published 01.11.2021 12:15:08
- Last modified 21.11.2024 05:55:32
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the searchPhrase parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administr...
CVE-2021-25874
- EPSS 0.83%
- Published 01.11.2021 12:15:07
- Last modified 21.11.2024 05:55:32
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.
CVE-2019-18662
- EPSS 0.3%
- Published 02.11.2019 15:15:10
- Last modified 21.11.2024 04:33:28
An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being u...
CVE-2019-5151
- EPSS 0.37%
- Published 31.10.2019 20:15:11
- Last modified 21.11.2024 04:44:26
An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could ...
CVE-2019-5150
- EPSS 0.37%
- Published 31.10.2019 20:15:11
- Last modified 21.11.2024 04:44:26
An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. When the "VideoTags" plugin is enabled, a specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the databas...
CVE-2019-5123
- EPSS 0.3%
- Published 25.10.2019 18:15:11
- Last modified 21.11.2024 04:44:23
Specially crafted web requests can cause SQL injections in YouPHPTube 7.6. An attacker can send a web request with Parameter dir in /objects/pluginSwitch.json.php.
CVE-2019-5122
- EPSS 0.51%
- Published 25.10.2019 18:15:11
- Last modified 21.11.2024 04:44:23
SQL injection vulnerabilities exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with Parameter name in /objects/pluginSwitch.json.php.