Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube.The parameter base64Url in /objects/getImageMP4.php is vulnerable to a command injection attack.
id: CVE-2019-5129
info:
name: YouPHPTube Encoder 2.3 - Command Injection
author: pussycat0x
s
...