Critical severity9.8NVD Advisory· Published Oct 25, 2019· Updated Jun 17, 2026
CVE-2019-5127
CVE-2019-5127
Description
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The parameter base64Url in /objects/getImage.php is vulnerable to a command injection attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:youphptube:youphptube_encoder:2.3:*:*:*:*:*:*:*
- YouPHPTube/YouPHPTube Encoderdescription
- Range: <=2.3
Patches
Vulnerability mechanics
References
1- talosintelligence.com/vulnerability_reports/TALOS-2019-0917nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.