Daniel Neto
98 exploits
Active since Dec 2025
AVideo has an IDOR - Any Admin Can Set Another User's Channel Password via setPassword.json.php
CVSS 9.1
AVideo has Unauthenticated SSRF via `webSiteRootURL` Parameter in saveDVR.json.php, Chaining to Verification Bypass
CVSS 9.1
AVideo has an Unauthenticated SQL Injection via `doNotShowCats` Parameter (Backslash Escape Bypass)
CVSS 9.8
AVideo has an authenticated arbitrary local file read via `chunkFile` path injection in `aVideoEncoder.json.php`
CVSS 7.6
AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection
CVSS 10.0
AVideo has PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through CSRF Against Admin
CVSS 8.8
AVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks Proxy
CVSS 8.6
AVideo has an OS Command Injection via $() Shell Substitution Bypass in sanitizeFFmpegCommand()
CVSS 8.1
AVideo Affected by Unauthenticated Disk Space Exhaustion via Unlimited Temp File Creation in aVideoEncoderChunk.json.php
CVSS 7.5
AVideo has an Unauthenticated Blind SQL Injection in RTMP on_publish Callback via Stream Name Parameter
CVSS 7.5
AVideo has a PGP 2FA Bypass via Cryptographically Broken 512-bit RSA Key Generation in LoginControl Plugin
CVSS 7.4
AVideo has Session Fixation via GET PHPSESSID Parameter With Disabled Login Session Regeneration
CVSS 7.3
AVideo has a Path Traversal in import.json.php that Allows Private Video Theft and Arbitrary File Read/Deletion via fileURI Parameter
CVSS 7.1
AVideo has Reflected XSS via unlockPassword Parameter in forbiddenPage.php and warningPage.php
CVSS 6.1
AVideo Vulnerable to Stored XSS via Markdown `javascript:` URI Bypasses ParsedownSafeWithLinks Sanitization
CVSS 5.4
AVideo has Unauthenticated Information Disclosure of User Group Permission Mappings via Permissions Plugin
CVSS 5.3
AVideo has Unauthenticated SSRF via plugin/Live/test.php
CVSS 9.3
AVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Execution via Malicious Plugin Upload
CVSS 8.8
AVideo has Authorization Bypass via Path Traversal in HLS Endpoint Allows Streaming Private/Paid Videos
CVSS 7.5
AVideo Affected by Arbitrary File Deletion via Path Traversal in CloneSite deleteDump Parameter
CVSS 8.1
AVideo has SSRF in BulkEmbed Thumbnail Fetch that Allows Reading Internal Network Resources
CVSS 5.0
AVideo Vulnerable to Stored XSS via Unescaped Video Title in CDN downloadButtons.php
CVSS 5.4
AVideo has an Open Redirect via Unvalidated redirectUri in userLogin.php
CVSS 6.1
AVideo Vulnerable to OS Command Injection via Unescaped URL in LinkedIn Video Upload Shell Command
CVSS 5.9
AVideo has SSRF in Scheduler Plugin via callbackURL Missing `isSSRFSafeURL()` Validation
CVSS 5.5