Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
AVideo before 29.0 OS Command Injection via execAsync
Vulnerability Description
AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live plugin on_publish.php endpoint despite escapeshellarg() protection.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
WWBN AVideo 命令注入漏洞
Vulnerability Description
WWBN avideo是WWBN组织开源的一套视频内容管理系统。 WWBN AVideo 29.0之前版本存在命令注入漏洞,该漏洞源于execAsync()函数对已转义命令重新包装在双引号sh -c中导致命令替换,攻击者可通过Live插件on_publish.php端点注入任意OS命令。
CVSS Information
N/A
Vulnerability Type
N/A