Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Metinfo Subscribe
Total 53 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-11500 1 Metinfo 1 Metinfo 2020-03-03 5.0 MEDIUM 7.5 HIGH
A directory traversal vulnerability exists in MetInfo 5.3.17. A remote attacker can use ..\ to delete any .zip file via the filenames parameter to /admin/system/database/filedown.php.
CVE-2019-17676 1 Metinfo 1 Metinfo 2019-10-21 6.8 MEDIUM 8.8 HIGH
app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI.
CVE-2019-17553 1 Metinfo 1 Metinfo 2019-10-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI.
CVE-2019-17418 1 Metinfo 1 Metinfo 2019-10-10 6.5 MEDIUM 7.2 HIGH
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997.
CVE-2019-17419 1 Metinfo 1 Metinfo 2019-10-10 6.5 MEDIUM 7.2 HIGH
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=user&c=admin_user&a=doGetUserInfo id parameter.
CVE-2019-16996 1 Metinfo 1 Metinfo 2019-10-04 6.5 MEDIUM 7.2 HIGH
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?n=product&c=product_admin&a=dopara&app_type=shop id parameter.
CVE-2019-16997 1 Metinfo 1 Metinfo 2019-10-04 6.5 MEDIUM 7.2 HIGH
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.
CVE-2017-11347 1 Metinfo 1 Metinfo 2019-10-02 6.5 MEDIUM 8.8 HIGH
Authenticated Code Execution Vulnerability in MetInfo 5.3.17 allows a remote authenticated attacker to generate a PHP script with the content of a malicious image, related to admin/include/common.inc.php and admin/app/physical/physical.php.
CVE-2018-9934 1 Metinfo 1 Metinfo 2019-10-02 4.3 MEDIUM 8.8 HIGH
The reset-password feature in MetInfo 6.0 allows remote attackers to change arbitrary passwords via vectors involving a Host HTTP header that is modified to specify a web server under the attacker's control.
CVE-2019-13969 1 Metinfo 1 Metinfo 2019-07-19 6.5 MEDIUM 8.8 HIGH
Metinfo 6.x allows SQL Injection via the id parameter in an admin/index.php?n=ui_set&m=admin&c=index&a=doget_text_content&table=lang&field=1 request.
CVE-2017-12789 1 Metinfo 1 Metinfo 2019-05-13 6.8 MEDIUM 8.8 HIGH
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the malicious link in the login state.
CVE-2017-12790 1 Metinfo 1 Metinfo 2019-05-09 4.3 MEDIUM 6.5 MEDIUM
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/index.php. The attack vector is: The administrator clicks on the malicious link in the login state.
CVE-2017-12788 1 Metinfo 1 Metinfo 2019-05-09 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in Metinfo 5.3.18 allows remote attackers to inject arbitrary web script or HTML via the (1) class1 parameter or the (2) anyid parameter.
CVE-2019-7718 1 Metinfo 1 Metinfo 2019-02-11 6.8 MEDIUM 8.1 HIGH
An issue was discovered in Metinfo 6.x. An attacker can leverage a race condition in the backend database backup function to execute arbitrary PHP code via admin/index.php?n=databack&c=index&a=dogetsql&tables=<?php and admin/databack/bakup_tables.php?2=file_put_contents URIs because app/system/databack/admin/index.class.php creates bakup_tables.php temporarily.
CVE-2018-20486 1 Metinfo 1 Metinfo 2019-01-14 4.3 MEDIUM 6.1 MEDIUM
MetInfo 6.x through 6.1.3 has XSS via the /admin/login/login_check.php url_array[] parameter.
CVE-2018-19051 1 Metinfo 1 Metinfo 2018-12-07 4.3 MEDIUM 6.1 MEDIUM
MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword abt_type parameter.
CVE-2018-19050 1 Metinfo 1 Metinfo 2018-12-07 4.3 MEDIUM 6.1 MEDIUM
MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword langset parameter.
CVE-2018-19835 1 Metinfo 1 Metinfo 2018-12-07 4.3 MEDIUM 6.1 MEDIUM
Metinfo 6.1.3 has reflected XSS via the admin/column/move.php lang_columnerr4 parameter.
CVE-2018-18296 1 Metinfo 1 Metinfo 2018-11-28 4.3 MEDIUM 6.1 MEDIUM
MetInfo 6.1.2 has XSS via the /admin/index.php bigclass parameter in an n=column&a=doadd action.
CVE-2018-18374 1 Metinfo 1 Metinfo 2018-11-27 3.5 LOW 5.4 MEDIUM
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.