Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2017-14513
Disclosure Date: September 17, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in MetInfo 5.3.17 allows remote attackers to read information from any ini format file via the f_filename parameter in a fingerprintdo action to admin/app/physical/physical.php.
0
Attacker Value
Unknown
CVE-2017-11500
Disclosure Date: July 20, 2017 (last updated November 26, 2024)
A directory traversal vulnerability exists in MetInfo 5.3.17. A remote attacker can use ..\ to delete any .zip file via the filenames parameter to /admin/system/database/filedown.php.
0
Attacker Value
Unknown
CVE-2017-9764
Disclosure Date: July 19, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in MetInfo 5.3.17 allows remote attackers to inject arbitrary web script or HTML via the Client-IP or X-Forwarded-For HTTP header to /include/stat/stat.php in a para action.
0
Attacker Value
Unknown
CVE-2017-11347
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Authenticated Code Execution Vulnerability in MetInfo 5.3.17 allows a remote authenticated attacker to generate a PHP script with the content of a malicious image, related to admin/include/common.inc.php and admin/app/physical/physical.php.
0