Show filters
46 Total Results
Displaying 1-10 of 46
Sort by:
Attacker Value
Unknown

CVE-2023-50172

Disclosure Date: January 10, 2024 (last updated January 04, 2025)
A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to the silent creation of a recovery pass code for any user.
Attacker Value
Unknown

CVE-2023-49864

Disclosure Date: January 10, 2024 (last updated January 17, 2024)
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_image` parameter.
Attacker Value
Unknown

CVE-2023-49863

Disclosure Date: January 10, 2024 (last updated January 19, 2024)
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_webpimage` parameter.
Attacker Value
Unknown

CVE-2023-49862

Disclosure Date: January 10, 2024 (last updated January 19, 2024)
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_gifimage` parameter.
Attacker Value
Unknown

CVE-2023-49810

Disclosure Date: January 10, 2024 (last updated January 18, 2024)
A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to captcha bypass, which can be abused by an attacker to brute force user credentials. An attacker can send a series of HTTP requests to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-49738

Disclosure Date: January 10, 2024 (last updated January 18, 2024)
An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.
Attacker Value
Unknown

CVE-2023-49715

Disclosure Date: January 10, 2024 (last updated January 18, 2024)
A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution when chained with an LFI vulnerability. An attacker can send a series of HTTP requests to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-49599

Disclosure Date: January 10, 2024 (last updated January 04, 2025)
An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via HTTP requests and brute force the salt offline, leading to forging a legitimate password recovery code for the admin user.
Attacker Value
Unknown

CVE-2023-49589

Disclosure Date: January 10, 2024 (last updated January 18, 2024)
An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-48730

Disclosure Date: January 10, 2024 (last updated January 18, 2024)
A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.