# YouPHPTube 7.8 跨站脚本漏洞
N/A
是否为 Web 类漏洞: 未知
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
标题: YouPHPTube<= 7.8 - Multiple Vulnerabilities - PHP webapps Exploit -- 🔗来源链接
标签:exploit
神龙速读:
## 关键信息
- **漏洞标题**: YouPHPTube <= 7.8 - Multiple Vulnerabilities
- **EDB-ID**: 51101
- **CVE**: N/A
- **作者**: Rafael Pedrero
- **类型**: WEBAPPS
- **平台**: PHP
- **日期**: 2023-03-28
- **易受攻击的应用**: YouPHPTube
- **漏洞类型**: LFI + Path Traversal, Reflected Cross-Site Scripting (XSS)
- **CVSS v3**: 7.5 (LFI), 6.5 (XSS)
- **CWE**: CWE-829, CWE-22 (LFI), CWE-79 (XSS)
- **测试版本**: 7.8
- **测试环境**: Windows 7, 10 using XAMPP
## 漏洞描述
### LFI + Path Traversal
- **问题**: YouPHPTube v7.8允许未经授权的目录访问。
- **参数**: "lang" 可以被修改并加载服务器上的PHP文件。
- **利用示例**: `http://127.0.0.1/youphptube/?lang=../phpinfo`
### Reflected Cross-Site Scripting (XSS)
- **问题**: YouPHPTube 7.8及以下版本未充分编码用户控制的输入,导致通过 `redirectUri` 参数的反射型XSS漏洞。
- **利用示例**: `http://localhost/<YouPHPTube_path_directory>/signup?redirectUri="()%26%25<ScRipt>alert(1)</ScRipt>`
标题: YouPHPTube <= 7.8 - Cross-Site Scripting | Advisories | VulnCheck -- 🔗来源链接
标签:third-party-advisory
神龙速读:
# YouPHPTube <= 7.8 - Cross-Site Scripting
## Key Information
- **Severity**: MEDIUM
- **Date**: January 13, 2026
- **Affecting**: YouPHPTube <= 7.8
- **CVE**: CVE-2021-47750
- **CWE**: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- **CVSS**: CVSS:3.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
- **Exploit**: ExploitDB-51101
- **Archived Homepage**: Archived YouPHPTube Homepage
- **Credit**: Rafael Pedrero
## Description
YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the redirectUri parameter in the signup page. Attackers can craft special signup URLs with embedded script tags to execute arbitrary JavaScript in victims' browsers when they access the signup page.
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.