VYPR

Youphptube

by Youphptube

Source repositories

CVEs (23)

  • CVE-2019-5129CriOct 25, 2019
    risk 0.67cvss 9.8epss 0.39

    A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The…

  • CVE-2019-5127CriOct 25, 2019
    risk 0.67cvss 9.8epss 0.45

    A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The…

  • CVE-2019-5128CriOct 25, 2019
    risk 0.66cvss 9.8epss 0.30

    A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The…

  • CVE-2019-5151CriOct 31, 2019
    risk 0.65cvss 10.0epss 0.02

    An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to…

  • CVE-2019-18662CriNov 2, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used to construct a SQL query.…

  • CVE-2019-5114CriOct 25, 2019
    risk 0.64cvss 9.9epss 0.01

    An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability,…

  • CVE-2019-16124CriSep 9, 2019
    risk 0.59cvss 9.8epss 0.28

    In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.

  • CVE-2019-5150HigOct 31, 2019
    risk 0.58cvss 8.9epss 0.02

    An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. When the "VideoTags" plugin is enabled, a specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion,…

  • CVE-2019-5123HigOct 25, 2019
    risk 0.57cvss 8.8epss 0.01

    Specially crafted web requests can cause SQL injections in YouPHPTube 7.6. An attacker can send a web request with Parameter dir in /objects/pluginSwitch.json.php.

  • CVE-2019-5122HigOct 25, 2019
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerabilities exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with Parameter name in /objects/pluginSwitch.json.php.

  • CVE-2019-5121HigOct 25, 2019
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerabilities exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with Parameter uuid in /objects/pluginSwitch.json.php

  • CVE-2019-5120HigOct 25, 2019
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially…

  • CVE-2019-5119HigOct 25, 2019
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exist in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially…

  • CVE-2019-5117HigOct 25, 2019
    risk 0.57cvss 8.8epss 0.01

    Exploitable SQL injection vulnerabilities exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability,…

  • CVE-2019-5116HigOct 25, 2019
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause a SQL injection. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially…

  • CVE-2021-25874HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.02

    AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.

  • CVE-2021-25877HigNov 1, 2021
    risk 0.47cvss 7.2epss 0.02

    AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.

  • CVE-2021-47750MedJan 13, 2026
    risk 0.40cvss 6.1epss 0.00

    YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the redirectUri parameter in the signup page. Attackers can craft special signup URLs with embedded script tags to execute arbitrary JavaScript in victims'…

  • CVE-2021-25878MedNov 1, 2021
    risk 0.40cvss 6.1epss 0.01

    AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.

  • CVE-2021-25876MedNov 1, 2021
    risk 0.40cvss 6.1epss 0.01

    AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.

Page 1 of 2