Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2023-50172
Disclosure Date: January 10, 2024 (last updated January 04, 2025)
A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to the silent creation of a recovery pass code for any user.
0
Attacker Value
Unknown
CVE-2023-49864
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_image` parameter.
0
Attacker Value
Unknown
CVE-2023-49810
Disclosure Date: January 10, 2024 (last updated January 18, 2024)
A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to captcha bypass, which can be abused by an attacker to brute force user credentials. An attacker can send a series of HTTP requests to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2023-49738
Disclosure Date: January 10, 2024 (last updated January 18, 2024)
An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.
0
Attacker Value
Unknown
CVE-2023-49715
Disclosure Date: January 10, 2024 (last updated January 18, 2024)
A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution when chained with an LFI vulnerability. An attacker can send a series of HTTP requests to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2023-49599
Disclosure Date: January 10, 2024 (last updated January 04, 2025)
An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via HTTP requests and brute force the salt offline, leading to forging a legitimate password recovery code for the admin user.
0
Attacker Value
Unknown
CVE-2023-49589
Disclosure Date: January 10, 2024 (last updated January 18, 2024)
An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2023-48730
Disclosure Date: January 10, 2024 (last updated January 18, 2024)
A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2023-47862
Disclosure Date: January 10, 2024 (last updated January 18, 2024)
A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send a series of HTTP requests to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2023-47861
Disclosure Date: January 10, 2024 (last updated January 18, 2024)
A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
0