S4E just found an informational finding from tcp full port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2019-5128

9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The parameter base64Url in /objects/getImageMP4.php is vulnerable to a command injection attack.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
youphptube
Updated Sep 28, 2026View on NVD →
S4E scanner

CVE-2019-5128 Scanner

This scanner targets the base64Url parameter in /objects/getImageMP4.php, allowing remote attackers to execute arbitrary OS commands on the server.

Used 2.6k times · 3.3k assets checked · domain, subdomain, ipv4

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →