ZeroHour

Vulnerabilities

23 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-47749
+1 in the same advisory: …47750
YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the 'lang' param

YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the 'lang' parameter in GET requests. Attackers can exploit the path traversal flaw in locale/function.php to include and view PHP files outside the intended directory by using directory traversal sequences.

NVD description · AI analysis pending
8.7
group max
2% PoC
  • youphptube youphptube
CVE-2021-25874
+4 in the same advisory: …25877 …25876 …25875 …25878
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated a

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.

NVD description · AI analysis pending
7.5
group max
2% PoC
  • youphptube youphptube
CVE-2019-18662
An issue was discovered in YouPHPTube through 7.7.

An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used to construct a SQL query. This can be exploited by malicious users to, e.g., read sensitive data from the database through in-band SQL Injection attacks. Successful exploitation of this vulnerability requires the Live Chat plugin to be enabled.

NVD description · AI analysis pending
9.82%
  • youphptube youphptube
CVE-2019-5151
+1 in the same advisory: …5150
An exploitable SQL injection vulnerability exist in YouPHPTube 7.7.

An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to code execution. An attacker can send an HTTP request to trigger this vulnerability.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • youphptube youphptube
CVE-2019-5127
+2 in the same advisory: …5129 …5128
A command injection have been found in YouPHPTube Encoder.

A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The parameter base64Url in /objects/getImage.php is vulnerable to a command injection attack.

NVD description · AI analysis pending
9.845% PoC
  • youphptube youphptube encoder
CVE-2019-5114
An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6.

An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and,in certain configuration, access the underlying operating system.

NVD description · AI analysis pending
9.9
group max
1% PoC
  • youphptube youphptube
CVE-2019-16124
In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert

In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.

NVD description · AI analysis pending
9.828% PoC
  • youphptube youphptube
CVE-2019-14430
plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.

plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.

NVD description · AI analysis pending
5.33% PoC
  • youphptube youphptube