CVE-2019-5121
- EPSS 0.49%
- Veröffentlicht 25.10.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:44:23
SQL injection vulnerabilities exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with Parameter uuid in /objects/pluginSwitch.json.php
CVE-2019-5120
- EPSS 0.51%
- Veröffentlicht 25.10.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:44:23
An exploitable SQL injection vulnerability exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger thi...
CVE-2019-5119
- EPSS 0.45%
- Veröffentlicht 25.10.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:44:23
An exploitable SQL injection vulnerability exist in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this...
CVE-2019-5117
- EPSS 0.49%
- Veröffentlicht 25.10.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:44:23
Exploitable SQL injection vulnerabilities exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger t...
CVE-2019-5116
- EPSS 0.49%
- Veröffentlicht 25.10.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:44:22
An exploitable SQL injection vulnerability exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause a SQL injection. An attacker can send a web request with parameters containing SQL injection attacks to trigger th...
CVE-2019-5114
- EPSS 0.56%
- Veröffentlicht 25.10.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:44:22
An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger ...
CVE-2019-16124
- EPSS 2.12%
- Veröffentlicht 09.09.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 04:30:05
In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.
CVE-2019-14430
- EPSS 1.85%
- Veröffentlicht 20.08.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:26:44
plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.