Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ampache | Ampache | 3.8.3 (including) | 3.8.3 (including) |
Ampache | Ubuntu | esm-apps/xenial | * |
Ampache | Ubuntu | trusty | * |
Ampache | Ubuntu | upstream | * |
Ampache | Ubuntu | xenial | * |