← Back

Metinfo

metinfo

Vendor: Metinfo • 60 CVEs

CVEs (60)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Metinfo
1Metinfo
Nov 21, 2024
Jul 12, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage.
1Metinfo
1Metinfo
Nov 21, 2024
Jul 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database information.
1Metinfo
1Metinfo
Nov 21, 2024
Jun 21, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability in MetInfo 7.0.0 via the gourl parameter in login.php.
1Metinfo
1Metinfo
Nov 21, 2024
May 24, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/language/admin/language_general.class.php and app/system/include/function/file.func.php.
1Metinfo
1Metinfo
Nov 21, 2024
Sep 30, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndata=yes&endata=yes&showdata=yes URI.
1Metinfo
1Metinfo
Nov 21, 2024
Oct 17, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI.
1Metinfo
1Metinfo
Nov 21, 2024
Oct 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI.
1Metinfo
1Metinfo
Nov 21, 2024
Oct 10, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=user&c=admin_user&a=doGetUserInfo id parameter.
1Metinfo
1Metinfo
Nov 21, 2024
Oct 10, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997.
1Metinfo
1Metinfo
Nov 21, 2024
Sep 30, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.
1Metinfo
1Metinfo
Nov 21, 2024
Sep 30, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?n=product&c=product_admin&a=dopara&app_type=shop id parameter.
1Metinfo
1Metinfo
Nov 21, 2024
Jul 19, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Metinfo 6.x allows SQL Injection via the id parameter in an admin/index.php?n=ui_set&m=admin&c=index&a=doget_text_content&table=lang&field=1 request.
1Metinfo
1Metinfo
Nov 21, 2024
May 10, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the...Show more
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the malicious link in the login state.Show less
1Metinfo
1Metinfo
Nov 21, 2024
May 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/index.php. The attack vector is: The administrator clicks on the malicious link in...Show more
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/index.php. The attack vector is: The administrator clicks on the malicious link in the login state.Show less
1Metinfo
1Metinfo
Nov 21, 2024
May 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in Metinfo 5.3.18 allows remote attackers to inject arbitrary web script or HTML via the (1) class1 parameter or the (2) anyid parameter.
1Metinfo
1Metinfo
Nov 21, 2024
Feb 11, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Metinfo 6.x. An attacker can leverage a race condition in the backend database backup function to execute arbitrary PHP code via admin/index.php?n=databack&c=index&a=dogetsql&tables=<?php and a...Show more
An issue was discovered in Metinfo 6.x. An attacker can leverage a race condition in the backend database backup function to execute arbitrary PHP code via admin/index.php?n=databack&c=index&a=dogetsql&tables=<?php and admin/databack/bakup_tables.php?2=file_put_contents URIs because app/system/databack/admin/index.class.php creates bakup_tables.php temporarily.Show less
1Metinfo
1Metinfo
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MetInfo 6.x through 6.1.3 has XSS via the /admin/login/login_check.php url_array[] parameter.
1Metinfo
1Metinfo
Nov 21, 2024
Dec 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), and common.inc.php allows registering variables from the $_COOKIE value. This issue can, for example,...Show more
In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), and common.inc.php allows registering variables from the $_COOKIE value. This issue can, for example, be exploited in conjunction with CVE-2018-19835 to bypass many XSS filters such as the Chrome XSS filter.Show less
1Metinfo
1Metinfo
Nov 21, 2024
Dec 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Metinfo 6.1.3 has reflected XSS via the admin/column/move.php lang_columnerr4 parameter.
1Metinfo
1Metinfo
Nov 21, 2024
Nov 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword abt_type parameter.