漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
AVideo through 29.0 OS Command Injection via ffmpeg.json.php
Vulnerability Description
AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping. Attackers who can craft a valid encrypted payload can inject arbitrary shell metacharacters into these fields to execute OS commands as the web-server user.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
WWBN AVideo 命令注入漏洞
Vulnerability Description
WWBN avideo是WWBN组织开源的一套视频内容管理系统。 WWBN AVideo 29.0及之前版本存在命令注入漏洞,该漏洞源于ffmpeg.json.php端点中notifyCode和callback参数未经转义直接拼接至shell命令,导致远程命令注入,攻击者可通过构造加密有效载荷注入任意shell元字符,以Web服务器用户身份执行OS命令。
CVSS Information
N/A
Vulnerability Type
N/A