Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2017-11715
Disclosure Date: July 28, 2017 (last updated November 26, 2024)
job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins to execute arbitrary PHP code by uploading a .phtml file after certain actions involving admin/system/safe.php and job/cv.php.
0
Attacker Value
Unknown
CVE-2017-11717
Disclosure Date: July 28, 2017 (last updated November 26, 2024)
MetInfo through 5.3.17 accepts the same CAPTCHA response for 120 seconds, which makes it easier for remote attackers to bypass intended challenge requirements by modifying the client-server data stream, as demonstrated by the login/findpass page.
0
Attacker Value
Unknown
CVE-2017-11718
Disclosure Date: July 28, 2017 (last updated November 26, 2024)
There is URL Redirector Abuse in MetInfo through 5.3.17 via the gourl parameter to member/login.php.
0
Attacker Value
Unknown
CVE-2017-11716
Disclosure Date: July 28, 2017 (last updated November 26, 2024)
MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode.
0