RULE(RULE ID:330742)

Rule General Information
Release Date: 2020-08-24
Rule Name: YouPHPTube Encoder getImage.php Command Injection Vulnerability (CVE-2019-5127)
Severity:
CVE ID:
Rule Protection Details
Description: A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The parameter base64Url in /objects/getImage.php is vulnerable to a command injection attack.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Others
Reference: https://talosintelligence.com/vulnerability_reports/TALOS-2019-0917
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.youphptube.com/