CVE-2024-31819 is a critical remote code execution vulnerability in WWBN AVideo, affecting versions 12.4 through 14.2. The issue is in the WWBNIndex plugin, specifically the submitIndex.php component, where the systemRootPath parameter can be attacker-controlled. According to the provided content, a remote attacker can send a crafted POST request to submitIndex.php with a malicious PHP filter chain via systemRootPath, resulting in arbitrary code execution on the server. The flaw is described as unauthenticated and exploitable remotely, with public proof-of-concept code and a Metasploit module available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting an unauthenticated remote code execution (RCE) vulnerability (CVE-2024-31819) in the WWBNIndex plugin of the AVideo platform. The exploit leverages improper input sanitization in the submitIndex.php file, allowing attackers to use PHP filter chain techniques to execute arbitrary PHP code or system commands on the server. The module is weaponized, supporting multiple payloads (PHP, Unix, Windows) and does not require authentication, making it highly dangerous. The main endpoints targeted are /plugin/WWBNIndex/submitIndex.php for exploitation and /index.php for version checking. The exploit is effective against AVideo versions 12.4 through 14.2 with the vulnerable plugin enabled. The repository is structured as a standard Metasploit module, written in Ruby, and is ready for operational use within the Metasploit framework.
This repository provides a Python-based exploit for CVE-2024-31819, targeting the WWBNIndex plugin. The main exploit logic resides in 'exploit.py', which takes a target URL and a command to execute. It leverages a sophisticated PHP filter chain generator (implemented in 'php_filter_chain.py') to craft a payload that abuses PHP's stream filters, enabling remote code execution via a POST request to '/plugin/WWBNIndex/submitIndex.php'. The payload is a PHP snippet that executes arbitrary system commands and marks the output for easy parsing. The exploit saves successful results to 'output.txt'. The repository includes a 'requirements.txt' for dependencies (colorama, requests) and a README with usage instructions. The attack vector is network-based, requiring access to the vulnerable endpoint. No hardcoded IPs or domains are present; the endpoint path is fingerprintable. The exploit is operational, providing real command execution if the target is vulnerable.
This repository provides a weaponized exploit for CVE-2024-31819, a critical unauthenticated remote code execution (RCE) vulnerability in the WWBNIndex plugin of the AVideo platform (versions 12.4 to 14.2). The vulnerability is due to improper handling of the 'systemRootPath' POST parameter in submitIndex.php, which is used unsafely in a require_once statement, allowing arbitrary PHP code execution via PHP filter chains. The repository includes: - A Python exploit script (exploit.py) that can test single or multiple targets, check for vulnerable versions, and provide an interactive shell for command execution on compromised servers. It uses a helper (php_filter_chain.py) to generate the necessary PHP filter chain payloads. - A Metasploit module (modules/exploits/multi/http/avideo_wwbnindex_unauth_rce.rb) that automates exploitation and supports various payloads (PHP, Linux, Windows meterpreter, etc.), making the exploit highly customizable and operational. - Documentation and a detailed README describing the vulnerability, affected versions, exploitation steps, and usage instructions. The main attack vector is a network-based POST request to the /plugin/WWBNIndex/submitIndex.php endpoint, with a malicious 'systemRootPath' parameter. Successful exploitation grants unauthenticated attackers full command execution on the target server, with the ability to spawn reverse shells or run arbitrary commands. The exploit is mature, weaponized, and suitable for both manual and automated exploitation via Metasploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in AVideo WWBNIndex functionality, referenced as a Metasploit module PR.
A critical vulnerability in AVideo with potential for full system takeover.
Remote code execution in WWBN AVideo v12.4 through v14.2 via systemRootPath parameter in submitIndex.php.
A remote code execution vulnerability in AVideo, for which detection artifacts and exploit code exist.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.