Loading
Generated remediation guidance and an executive summary. No account required.
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The parameter base64Url in /objects/getSpiritsFromVideo.php is vulnerable to a command injection attack.
Use CWE-78, Youphptube vendor hub and Youphptube Encoder product page to widen CVE-2019-5129 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-5128 and CVE-2019-5127 for nearby disclosures in the same product family.