CVE-2024-31819
CRITICALWWBN AVideo 12.4-14.2 - Remote Code Execution via systemRootPath Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2024-31819.
PoCs published by Chocapikk, dream434, Valentin Lobstein, including Metasploit module exploits/multi/http/avideo_wwbnindex_unauth_rce.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2024-31819, an unauthenticated RCE vulnerability in the AVideo platform's WWBNIndex plugin. The exploit leverages improper input validation in the `submitIndex.php` file to execute arbitrary PHP code via a crafted `systemRootPath` parameter.
Description
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.
Exploits (3)
This repository contains a functional exploit for CVE-2024-31819, an unauthenticated RCE vulnerability in the AVideo platform's WWBNIndex plugin. The exploit leverages improper input validation in the `submitIndex.php` file to execute arbitrary PHP code via a crafted `systemRootPath` parameter.
This repository contains a functional exploit for CVE-2024-31819, leveraging PHP filter chains to achieve remote code execution (RCE) via a crafted payload sent to a vulnerable endpoint. The exploit uses a series of PHP iconv conversions to bypass restrictions and execute arbitrary commands.
This Metasploit module exploits an unauthenticated RCE vulnerability in the AVideo WWBNIndex plugin by leveraging PHP filter chaining to execute arbitrary code via the `require()` function in `submitIndex.php`. It supports multiple payload types (PHP, Unix, Windows) and includes version checking for vulnerability confirmation.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H