Files
metasploit-gs/modules/exploits
Valentin Lobstein dfe73bb4c5 Add exploit for AVideo Encoder getImage.php command injection (CVE-2026-29058)
Unauthenticated OS command injection via the base64Url parameter in
getImage.php. The URL is interpolated into an ffmpeg shell command
without escapeshellarg(), and FILTER_VALIDATE_URL does not block
shell metacharacters in the URL path.
2026-03-06 21:30:12 +01:00
..
2026-02-12 13:45:06 -05:00
2025-12-18 10:08:31 -05:00
2026-03-02 15:02:56 +00:00