CVE-2021-47749
MEDIUMYouPHPTube <= 7.8 - Unauthenticated Path Traversal via Lang Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47749. PoCs published by Rafael Pedrero.
AI-analyzed exploit summary The exploit demonstrates a Local File Inclusion (LFI) vulnerability in YouPHPTube <= 7.8 via the 'lang' parameter, allowing unauthenticated path traversal to include arbitrary files. It also includes a reflected XSS proof-of-concept via the 'redirectUri' parameter.
Description
YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the 'lang' parameter in GET requests. Attackers can exploit the path traversal flaw in locale/function.php to include and view PHP files outside the intended directory by using directory traversal sequences.
Exploits (1)
The exploit demonstrates a Local File Inclusion (LFI) vulnerability in YouPHPTube <= 7.8 via the 'lang' parameter, allowing unauthenticated path traversal to include arbitrary files. It also includes a reflected XSS proof-of-concept via the 'redirectUri' parameter.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N