Daniel Neto
118 exploits
Active since May 2023
AVideo has PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through CSRF Against Admin
CVSS 8.8
AVideo <=26.0 LiveLinks Proxy - Server-Side Request Forgery Bypass
CVSS 8.6
AVideo <=26.0 sanitizeFFmpegCommand - OS Command Injection
CVSS 8.1
AVideo Affected by Unauthenticated Disk Space Exhaustion via Unlimited Temp File Creation in aVideoEncoderChunk.json.php
CVSS 7.5
AVideo <=26.0 RTMP on_publish - Unauthenticated Blind SQL Injection
CVSS 7.5
AVideo <=26.0 LoginControl PGP - Two-Factor Authentication Bypass
CVSS 7.4
AVideo has Session Fixation via GET PHPSESSID Parameter With Disabled Login Session Regeneration
CVSS 7.3
AVideo <=26.0 import.json.php fileURI - Path Traversal
CVSS 7.1
AVideo has Reflected XSS via unlockPassword Parameter in forbiddenPage.php and warningPage.php
CVSS 6.1
AVideo Vulnerable to Stored XSS via Markdown `javascript:` URI Bypasses ParsedownSafeWithLinks Sanitization
CVSS 5.4
AVideo has Unauthenticated Information Disclosure of User Group Permission Mappings via Permissions Plugin
CVSS 5.3
AVideo has Unauthenticated SSRF via plugin/Live/test.php
CVSS 9.3
AVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Execution via Malicious Plugin Upload
CVSS 8.8
AVideo has Authorization Bypass via Path Traversal in HLS Endpoint Allows Streaming Private/Paid Videos
CVSS 7.5
AVideo Affected by Arbitrary File Deletion via Path Traversal in CloneSite deleteDump Parameter
CVSS 8.1
AVideo has SSRF in BulkEmbed Thumbnail Fetch that Allows Reading Internal Network Resources
CVSS 5.0
AVideo Vulnerable to Stored XSS via Unescaped Video Title in CDN downloadButtons.php
CVSS 5.4
AVideo <26.0 userLogin.php redirectUri - Open Redirect
CVSS 6.1
AVideo Vulnerable to OS Command Injection via Unescaped URL in LinkedIn Video Upload Shell Command
CVSS 5.9
AVideo has SSRF in Scheduler Plugin via callbackURL Missing `isSSRFSafeURL()` Validation
CVSS 5.5
AVideo <26.0 listFiles.json.php - Filesystem Enumeration
CVSS 4.3
AVideo-Encoder has Unauthenticated Blind Server-Side Request Forgery via Public Thumbnail Generator
CVSS 9.1
AVideo-Encoder is Vulnerable to Authenticated SQL Injection via ORDER BY Clause
CVSS 8.8
Unauthenticated Reflected XSS via innerHTML in AVideo
CVSS 6.1
WWBN AVideo has predictable default admin credentials in official Docker deployment path
CVSS 8.1