Youphptube

Youphptube

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 13.01.2026 22:56:03
  • Zuletzt bearbeitet 22.01.2026 20:27:30

YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the redirectUri parameter in the signup page. Attackers can craft special signup URLs with embedded script tags to execute arbit...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 13.01.2026 22:51:38
  • Zuletzt bearbeitet 26.01.2026 16:15:54

YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the 'lang' parameter in GET requests. Attackers can exploit the path traversal flaw in locale/function.php...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 01.11.2021 12:15:08
  • Zuletzt bearbeitet 21.11.2024 05:55:33

AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.

Exploit
  • EPSS 1.2%
  • Veröffentlicht 01.11.2021 12:15:08
  • Zuletzt bearbeitet 21.11.2024 05:55:33

AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.

Exploit
  • EPSS 0.44%
  • Veröffentlicht 01.11.2021 12:15:08
  • Zuletzt bearbeitet 21.11.2024 05:55:32

AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.

Exploit
  • EPSS 0.44%
  • Veröffentlicht 01.11.2021 12:15:08
  • Zuletzt bearbeitet 21.11.2024 05:55:32

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the searchPhrase parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administr...

Exploit
  • EPSS 0.83%
  • Veröffentlicht 01.11.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 05:55:32

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.

  • EPSS 0.32%
  • Veröffentlicht 02.11.2019 15:15:10
  • Zuletzt bearbeitet 21.11.2024 04:33:28

An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being u...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 31.10.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 04:44:26

An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. When the "VideoTags" plugin is enabled, a specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the databas...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 31.10.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 04:44:26

An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could ...