S4E just found a medium ssl lucky13 vulnerability scanner
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-5127 Scanner

CVE-2019-5127 scanner - Command Injection vulnerability in YouPHPTube Encoder

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-5127
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The parameter base64Url in /objects/getImage.php is vulnerable to a command injection attack.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
YouPHPTube"by n/a
YouPHPTube Encoder 2.3
Updated Aug 21, 2026View on NVD →
Detail

YouPHPTube Encoder is a plugin that provides encoder functionality in YouPHPTube. The YouPHPTube Encoder is an essential tool for YouPHPTube users, as it allows them to easily encode and upload videos onto their YouPHPTube account. This tool is essential for users who want to share their videos without compromising the quality of their content. 

CVE-2019-5127 is a vulnerability that has been detected in the YouPHPTube Encoder 2.3 plugin. This vulnerability is a command injection that can be exploited via the parameter base64Url in /objects/getImage.php. What this means is that an attacker can execute arbitrary commands on the server where the YouPHPTube Encoder plugin is installed, leading to a complete compromise of the server.

Exploiting this vulnerability can lead to an attacker gaining complete control of the server and being able to execute arbitrary commands on it. This can lead to the attacker stealing sensitive information, spreading malware, or even launching DDoS attacks on other websites. The consequences of an attack on a server can be catastrophic for any organization, and that is why it is important to protect against this vulnerability.

It is vital to stay up-to-date with current threats and vulnerabilities that could potentially affect your digital assets. Thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. By keeping yourself informed about potential threats, you can ensure the safety of your valuable digital assets.

 

REFERENCES

Solution Advice

The following precautions can be taken to protect against this vulnerability:

  • Update the YouPHPTube Encoder plugin to the latest version.
  • Use a Web Application Firewall(WAF) to filter out malicious requests.
  • Ensure that the server operating system is regularly updated and patched.
  • Review all code for vulnerabilities before deploying it on a server.
  • Use a strong and complex password for the server that is changed regularly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-5127 scanner - Command Injection vulnerability in YouPHPTube Encoder S4E