Vulnerabilities
Vulnerable Software
Metinfo:  >> Metinfo  Security Vulnerabilities
Metinfo 6.1.3 has reflected XSS via the admin/column/move.php lang_columnerr4 parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-12-03
In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), and common.inc.php allows registering variables from the $_COOKIE value. This issue can, for example, be exploited in conjunction with CVE-2018-19835 to bypass many XSS filters such as the Chrome XSS filter.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-12-03
MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword langset parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-11-07
MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword abt_type parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-11-07
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-10-16
MetInfo 6.1.2 has XSS via the /admin/index.php bigclass parameter in an n=column&a=doadd action.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-10-15
MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field.
CVSS Score
4.9
EPSS Score
0.002
Published
2018-09-17
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.
CVSS Score
4.8
EPSS Score
0.002
Published
2018-07-20
MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by an admin/index.php?anyid=47&n=admin&c=admin_admin&a=doaddsave URI.
CVSS Score
8.8
EPSS Score
0.002
Published
2018-07-20
Metinfo v6.0.0 allows remote attackers to write code into a .php file, and execute that code, via the module parameter to admin/column/save.php in an editor upload action.
CVSS Score
7.2
EPSS Score
0.008
Published
2018-06-29


Contact Us

Shodan ® - All rights reserved