CVE-2017-15956

ConverTo Video Downloader & Converter 1.4.1 allows Arbitrary File Download via the token parameter to download.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:converto_video_downloader_\&_converter_project:converto_video_downloader_\&_converter:1.4.1:*:*:*:*:*:*:*

History

21 Nov 2024, 03:15

Type Values Removed Values Added
References () https://packetstormsecurity.com/files/144456/ConverTo-Video-Downloader-And-Converter-1.4.1-Arbitrary-File-Download.html - Third Party Advisory, VDB Entry () https://packetstormsecurity.com/files/144456/ConverTo-Video-Downloader-And-Converter-1.4.1-Arbitrary-File-Download.html - Third Party Advisory, VDB Entry

Information

Published : 2017-10-29 06:29

Updated : 2024-11-21 03:15


NVD link : CVE-2017-15956

Mitre link : CVE-2017-15956

CVE.ORG link : CVE-2017-15956


JSON object : View

Products Affected

converto_video_downloader_\&_converter_project

  • converto_video_downloader_\&_converter
CWE
CWE-20

Improper Input Validation