AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.
References
Link | Resource |
---|---|
https://www.synacktiv.com/sites/default/files/2021-01/YouPHPTube_Multiple_Vulnerabilities.pdf | Exploit Vendor Advisory |
https://synacktiv.com | Product |
http://avideoyouphptube.com | Broken Link Product |
Configurations
Information
Published : 2021-11-01 05:15
Updated : 2022-07-12 10:42
NVD link : CVE-2021-25877
Mitre link : CVE-2021-25877
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
youphptube
- youphptube