Show filters
57 Total Results
Displaying 31-40 of 57
Sort by:
Attacker Value
Unknown
CVE-2018-19835
Disclosure Date: December 03, 2018 (last updated November 27, 2024)
Metinfo 6.1.3 has reflected XSS via the admin/column/move.php lang_columnerr4 parameter.
0
Attacker Value
Unknown
CVE-2018-19836
Disclosure Date: December 03, 2018 (last updated November 27, 2024)
In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), and common.inc.php allows registering variables from the $_COOKIE value. This issue can, for example, be exploited in conjunction with CVE-2018-19835 to bypass many XSS filters such as the Chrome XSS filter.
0
Attacker Value
Unknown
CVE-2018-19050
Disclosure Date: November 07, 2018 (last updated November 27, 2024)
MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword langset parameter.
0
Attacker Value
Unknown
CVE-2018-19051
Disclosure Date: November 07, 2018 (last updated November 27, 2024)
MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword abt_type parameter.
0
Attacker Value
Unknown
CVE-2018-18374
Disclosure Date: October 16, 2018 (last updated November 27, 2024)
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.
0
Attacker Value
Unknown
CVE-2018-18296
Disclosure Date: October 15, 2018 (last updated November 27, 2024)
MetInfo 6.1.2 has XSS via the /admin/index.php bigclass parameter in an n=column&a=doadd action.
0
Attacker Value
Unknown
CVE-2018-17129
Disclosure Date: September 17, 2018 (last updated November 27, 2024)
MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field.
0
Attacker Value
Unknown
CVE-2018-14420
Disclosure Date: July 20, 2018 (last updated November 27, 2024)
MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by an admin/index.php?anyid=47&n=admin&c=admin_admin&a=doaddsave URI.
0
Attacker Value
Unknown
CVE-2018-14419
Disclosure Date: July 20, 2018 (last updated November 27, 2024)
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.
0
Attacker Value
Unknown
CVE-2018-13024
Disclosure Date: June 29, 2018 (last updated November 26, 2024)
Metinfo v6.0.0 allows remote attackers to write code into a .php file, and execute that code, via the module parameter to admin/column/save.php in an editor upload action.
0