Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2026-33478 PoC — WWBN AVideo 安全漏洞

Source
Associated Vulnerability
Title:WWBN AVideo 安全漏洞 (CVE-2026-33478)
Description:WWBN AVideo是WWBN团队的一个由PHP编写的视频平台建站系统。 WWBN AVideo 26.0及之前版本存在安全漏洞,该漏洞源于CloneSite插件中的多个漏洞链式结合,可能导致未经身份验证的攻击者实现远程代码执行,包括泄露克隆密钥、触发数据库转储和利用OS命令注入。
Description
WWBN AVideo <= 26.0 contains multiple vulnerabilities in the CloneSite plugin including unauthenticated exposure of clone secret keys and OS command injection in rsync command construction, letting unauthenticated attackers achieve remote code execution.
File Snapshot

id: CVE-2026-33478 info: name: AVideo <= 26.0 - WWBN AVideo - Remote Code Execution author: pus ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.