Files
metasploit-gs/documentation/modules/exploit/linux/http
Valentin Lobstein dfe73bb4c5 Add exploit for AVideo Encoder getImage.php command injection (CVE-2026-29058)
Unauthenticated OS command injection via the base64Url parameter in
getImage.php. The URL is interpolated into an ffmpeg shell command
without escapeshellarg(), and FILTER_VALIDATE_URL does not block
shell metacharacters in the URL path.
2026-03-06 21:30:12 +01:00
..
2023-10-10 14:46:18 -04:00
2020-06-12 10:46:44 -04:00
2025-07-17 11:51:29 +01:00
2025-07-17 11:51:29 +01:00
2020-01-16 11:41:12 -05:00
2023-10-10 14:46:18 -04:00
2017-11-10 18:15:22 -06:00
2025-07-17 11:51:29 +01:00
2025-07-17 11:51:29 +01:00
2018-07-10 11:51:57 -05:00
2025-07-17 11:51:29 +01:00
2022-11-23 13:26:19 -06:00
2025-07-17 11:51:29 +01:00
2017-02-23 07:44:45 +00:00
2020-01-16 11:41:12 -05:00
2025-07-17 11:51:29 +01:00
2025-07-17 11:51:29 +01:00
2025-11-07 15:42:27 -05:00
2025-07-17 11:51:29 +01:00
2025-07-17 11:51:29 +01:00
2023-10-10 14:46:18 -04:00
2025-07-17 11:51:29 +01:00