Vulnerability Database

300,926

Total vulnerabilities in the database

AVideo contains Command injection when embedding a video link

Impact:

An attacker could execute remote code on a system running wwbn/avideo

Step to Reproduce:

  1. Go to the My Videos tab

https://demo.avideo.com/mvideos

  1. Click "Embed a video link"

Append a command to the url as a query string. eg. ?whoami

then click Save

This issue has been resolved in commit 236228f15

No technical information available.

No CWE or OWASP classifications available.