Daniel Neto
118 exploits
Active since May 2023
AVideo's IDOR in uploadPoster.php Allows Any Authenticated User to Overwrite Scheduled Live Stream Posters and Trigger False Socket Notifications
CVSS 5.4
AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket()
CVSS 5.4
AVideo has User Group-Based Category Access Control Bypass via Missing and Broken Group Filtering in categories.json.php
CVSS 5.3
AVideo Vulnerable to Wallet Balance Double-Spend via TOCTOU Race Condition in transferBalance
CVSS 5.3
AVIdeo has Video Password Protection Bypass via API Endpoints Returning Full Playback Sources Without Password Verification
CVSS 5.3
AVideo Vulnerable to Reflected XSS via Unsanitized plugin Parameter in YPTWallet Stripe Payment Page
CVSS 8.2
AVideo Vulnerable to Remote Code Execution via MIME/Extension Mismatch in ImageGallery File Upload
CVSS 8.8
AVideo's Video Moderator Privilege Escalation via Ownership Transfer Enables Arbitrary Video Deletion
CVSS 7.6
AVideo <=26.0 Live Schedule Reminder - Blind SQL Injection
CVSS 8.1
AVideo has Path Traversal in pluginRunDatabaseScript.json.php Enables Arbitrary SQL File Execution via Unsanitized Plugin Name
CVSS 7.2
AVideo Allows Unauthenticated Access to AD_Server reports.json.php that Exposes Ad Campaign Analytics and User Data
CVSS 5.3
AVideo has Pre-Captcha User Enumeration and Account Status Disclosure in Password Recovery Endpoint
CVSS 5.3
AVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.php
CVSS 9.4
AVideo Vulnerable to Remote Code Execution via Persistent PHP Temp File in Encoder downloadURL with Resolution Validation Abort
CVSS 8.8
AVideo Vulnerable to SQL Injection in Subscribe Endpoint via Unsanitized user_id Parameter in subscribe.php
CVSS 7.1
WWBN AVideo <=26.0 - Info Disclosure
CVSS 7.5
WWBN AVideo <=26.0 - Command Injection
CVSS 8.8
WWBN AVideo <= 26.0 - Stored Cross-Site Scripting via User Profile About Field
CVSS 5.4
WWBN AVideo <= 26.0 - IP Address Spoofing via HTTP Header Manipulation
CVSS 5.3
WWBN AVideo <= 26.0 - Unauthenticated CDN Configuration Modification via par Parameter
CVSS 8.6
AVideo <26.0 setPassword.json.php - Channel Password Bypass
CVSS 9.1
AVideo has Unauthenticated SSRF via `webSiteRootURL` Parameter in saveDVR.json.php, Chaining to Verification Bypass
CVSS 9.1
AVideo <26.0 doNotShowCats - Unauthenticated SQL Injection
CVSS 9.8
AVideo <=26.0 aVideoEncoder chunkFile - Local File Read
CVSS 7.6
AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection
CVSS 10.0