Daniel Neto
118 exploits
Active since May 2023
AVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deployments
CVSS 8.1
AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy
CVSS 8.6
AVideo <26.0 encryptPass.json.php - Password Hash Oracle
CVSS 5.3
AVideo affected by Session Hijacking via Unauthenticated Session ID Disclosure with Permissive CORS
CVSS 8.1
WWBN AVideo <25.0 - Info Disclosure
CVSS 5.3
WWBN AVideo < 24.0 - Unauthenticated SQL Injection via catName Parameter in JSON POST Request
CVSS 9.8
WWBN AVideo <24.0 - Authenticated RCE
CVSS 8.8
WWBN AVideo < 21.0 - Authenticated Stored Cross-Site Scripting via Markdown Link Injection
CVSS 6.1
WWBN AVideo < 22.0 - Authenticated Server-Side Request Forgery via aVideoEncoder.json.php DownloadURL Parameter
CVSS 8.1
AVideo < 20.1 - Unauthenticated Arbitrary File Upload and Deletion via ImageGallery Plugin
CVSS 9.1
AVideo < 20.1 - Authenticated Arbitrary File Deletion via IDOR
CVSS 6.5
AVideo < 20.1 - Authenticated Arbitrary File Upload via Insecure Direct Object Reference
CVSS 8.8
AVideo < 20.1 - Authenticated Arbitrary Comment Image Upload via Missing Ownership Check
CVSS 8.8
AVideo < 20.1 - Insecure Direct Object Reference in Video Rotation Metadata
CVSS 8.1
AVideo < 20.1 - Open Redirect via cancelUri Parameter
CVSS 6.1
AVideo < 20.1 - Open Redirect via siteRedirectUri Parameter
CVSS 6.1
AVideo < 20.1 - Unauthenticated Exposure of Sensitive User Information via Public API
CVSS 7.5
AVideo < 20.1 - Sensitive System Information Exposure via Public API Endpoints
CVSS 7.5