Daniel Neto
118 exploits
Active since May 2023
WWBN AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClient.json.php` Enables Cross-Site DB Dump of the Configured Clone Server
CVSS 7.5
WWBN AVideo: Incomplete Fix for YPTSocket autoEvalCodeOnHTML Strip: Unauthenticated Cross-User JavaScript Execution via `$msg['json']` Relay Bypass
CVSS 7.2
WWBN AVideo: Password Hash Leaked in MobileManager OAuth Redirect URL Enables Account Takeover
CVSS 6.8
WWBN AVideo: HTML Injection in notifySubscribers.json.php Enables Platform-Branded Phishing Emails to Channel Subscribers
CVSS 6.4
WWBN AVideo: CSRF in userSavePhoto.php Allows Cross-Origin Overwrite of Any Logged-in User's Profile Photo with Arbitrary Bytes
CVSS 5.4
WWBN AVideo: Reflected XSS in plugin/Meet/iframe.php via Unescaped `user`/`pass` Parameters Reflected into JavaScript String Literal
CVSS 6.1
WWBN AVideo: Blind SSRF in YPTWallet Donation Webhook via Missing isSSRFSafeURL() Check and CURLOPT_FOLLOWLOCATION Redirect Bypass
CVSS 5.4
WWBN AVideo: Unauthenticated Arbitrary Email Sending via sendEmail.json.php Allows Phishing from Site's Legitimate From Address
CVSS 5.3
WWBN AVideo <= 29.0 - Unauthenticated User Enumeration
CVSS 5.3
WWBN AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event Spoofing
CVSS 4.3
WWBN AVideo: IDOR in PayPalYPT agreementCancel.json.php Allows Any Authenticated User to Cancel Arbitrary PayPal Subscription Agreements
CVSS 4.2
WWBN AVideo: SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL()
CVSS 7.7
WWBN AVideo: Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization
WWBN AVideo < 12.4 - Remote Code Execution via CloneSite Plugin
CVSS 8.8
AVideo has Unauthenticated Information Disclosure of User Group Permission Mappings via Permissions Plugin
CVSS 5.3
WWBN AVideo LiveLinks Proxy - Server-Side Request Forgery
CVSS 8.6
AVideo <=29.0 CloneSite deleteDump - Path Traversal
CVSS 8.1
AVideo <=29.0 ReceiveImage downloadURL - Path Traversal
CVSS 6.5
WWBN AVideo ParsedownSafeWithLinks - Cross-Site Scripting
CVSS 5.4
AVideo <=29.0 test.php URL Handling - Command Injection
CVSS 9.3
WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs
CVSS 7.6
WWBN AVideo has IDOR in Live Restreams list.json.php that Exposes Other Users' Stream Keys and OAuth Tokens
CVSS 6.5
WWBN AVideo <= 29.0 - Path Traversal Remote Code Execution
CVSS 8.7
WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks
CVSS 10.0
WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials
CVSS 8.3