Claudio Bozzato
18 exploits
Active since Aug 2022
WWBN AVideo <11.6 - Info Disclosure
CVSS 6.5
WWBN AVideo 11.6 and dev master commit 3f7c0364 - Cross-Site Scripting in videoAddNew Functionality
CVSS 9.0
WWBN AVideo 11.6 and dev master commit 3f7c0364 - OS Command Injection via aVideoEncoder Chunkfile Functionality
CVSS 8.8
WWBN AVideo 11.6 and dev master commit 3f7c0364 - Path Traversal and Arbitrary Command Execution via unzipDirectory
CVSS 9.9
WWBN AVideo 11.6 and dev master commit 3f7c0364 - Cross-Site Scripting in Image403 Functionality
CVSS 6.1
WWBN AVideo 11.6 and dev master commit 3f7c0364 - Improper Authentication via Password Hash
CVSS 8.8
WWBN AVideo 11.6 and dev master commit 3f7c0364 - OS Command Injection via aVideoEncoder wget Functionality
CVSS 8.8
WWBN AVideo 11.6 and dev master - Arbitrary File Read via aVideoEncoderReceiveImage
CVSS 6.5
WWBN AVideo 11.6 and dev master commit 3f7c0364 - Authentication Bypass via Live Schedules Plugin ID Guessing
CVSS 4.2
WWBN AVideo 11.6 and dev master commit 3f7c0364 - Authenticated Authentication Bypass via Playlists Plugin ID Handling
CVSS 5.0
WWBN AVideo 11.6 and dev master commit 3f7c0364 - Cross-Site Scripting via Footer Alerts Toast Parameter
CVSS 6.1
WWBN AVideo 11.6 and dev master commit 3f7c0364 - Cross-Site Scripting via Footer Alerts Success Parameter
CVSS 6.1
WWBN AVideo 11.6 and dev master commit 3f7c0364 - Cross-Site Scripting via Footer Alerts msg Parameter
CVSS 6.1
WWBN AVideo 11.6 and dev master commit 3f7c0364 - Information Disclosure via Session Cookie
CVSS 7.5
WWBN AVideo 11.6-dev master - SQL Injection
CVSS 8.8
WWBN AVideo 11.6-dev master - SQL Injection
CVSS 8.8
WWBN AVideo 11.6-dev master - SQL Injection
CVSS 8.8
WWBN AVideo 11.6 and dev master commit 3f7c0364 - SQL Injection via Live Schedules Description Parameter
CVSS 8.8