.. / CVE-2019-5127

Exploit for YouPHPTube Encoder 2.3 - Remote Command Injection (CVE-2019-5127)

Description:

YouPHPTube Encoder 2.3 is susceptible to a command injection vulnerability which could allow an attacker to compromise the server. These exploitable unauthenticated command injections exist via the parameter base64Url in /objects/getImage.php.

Nuclei Template

View the template here CVE-2019-5127.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-5127.yaml
Copy

References:

https://github.com/Elsfa7-110/kenzer-templates
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0917
https://nvd.nist.gov/vuln/detail/CVE-2019-5127
https://github.com/ARPSyndicate/kenzer-templates
https://github.com/sobinge/nuclei-templates