vendor:
YouPHPTube
by:
Rafael Pedrero
7.5
CVSS
HIGH
LFI + Path Traversal, reflected Cross-Site Scripting (XSS)
829, 22, 79
CWE
Product Name: YouPHPTube
Affected Version From: YouPHPTube <= 7.8
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7, Windows 10 using XAMPP
2021
YouPHPTube <= 7.8 - Multiple Vulnerabilities
YouPHPTube v7.8 allows unauthenticated directory traversal and Local File Inclusion through the parameter in an /?lang=PATH+TRAVERSAL+FILE (without php) GET request. It also has a reflected Cross-Site Scripting (XSS) vulnerability.
Mitigation:
The vendor has not provided a patch or mitigation for these vulnerabilities.