An incomplete blacklist exists in the .htaccess sample of...
High severity
Unreviewed
Published
Jul 24, 2025
to the GitHub Advisory Database
•
Updated Jul 24, 2025
Description
Published by the National Vulnerability Database
Jul 24, 2025
Published to the GitHub Advisory Database
Jul 24, 2025
Last updated
Jul 24, 2025
An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can request a .phar file to trigger this vulnerability.
References