ClipBucket是MacWarrior开源的一个开源且可免费下载的 PHP 脚本。用于共享视频网站。 ClipBucket v5 5.5.2-#187及之前版本存在SQL注入漏洞,该漏洞源于对/actions/ajax.php端点中obj_id参数未经验证或清理,可能导致盲SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MacWarrior | clipbucket-v5 | <= 5.5.2-#187 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | ClipBucket v5.5.2-#187 and below contain a blind SQL injection caused by unsanitized obj_id parameter in /actions/ajax.php used in user_exists function, letting attackers perform blind SQL injection remotely, exploit requires crafted POST request. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-21875.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet