CVE-2022-32282 - Exploiting the AVideo Login Flaw for Direct Account Takeover
If you run or use WWBN AVideo for hosting video content, you need to know about CVE-2022-32282. This security vulnerability, found in AVideo
CVE-2022-30534 An OS command injection vulnerability exists in the WWBN AVideo 11.6 and dev master commit 3f7c0364 functionality of aVideoEncoder. A specially crafted HTTP request can lead to arbitrary command execution.
The request should contain the following parameters:
http://Vulnerable Server>/{aVideoEncoder}/{aVideoEncoder}/{path}?cmd={command}
An OS command injection vulnerability exists in the aVideoEncoder
CVE-2021-3639 A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly
This can be exploited when a site is configured to use the mod_auth_mellon authentication module. When a user accesses a site with a
CVE-2022-36198
A stored XSS vulnerability was detected on the buspassms/admin/view-enquiry.php script that is prone to hacking when user input is processed by
CVE-2022-36251 Clinic's Patient Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via patients.php
A remote attacker can inject malicious code into the system via this vector. An attacker can create a patient record with a script that causes
Episode
00:00:00
00:00:00