CVE-2021-47749
EUVD-2026-265213.01.2026, 23:15
YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the 'lang' parameter in GET requests. Attackers can exploit the path traversal flaw in locale/function.php to include and view PHP files outside the intended directory by using directory traversal sequences.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| youphptube | youphptube | 𝑥 ≤ 7.8 |
𝑥
= Vulnerable software versions