Metinfo Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2017-11715

    job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins to execute arbitrary PHP code by uploading a .phtml file after certain actions involving admin/system/safe.php and job/cv.php.

    Last Modified: Apr 20, 2025
    Published: Jul 28, 2017

    CVE-2017-11716

    MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode.

    Last Modified: Apr 20, 2025
    Published: Jul 28, 2017

    CVE-2017-11717

    MetInfo through 5.3.17 accepts the same CAPTCHA response for 120 seconds, which makes it easier for remote attackers to bypass intended challenge requirements by modifying the client-server data stream, as demonstrated by the login/findpass page.

    Last Modified: Apr 20, 2025
    Published: Jul 28, 2017

    CVE-2017-11718

    There is URL Redirector Abuse in MetInfo through 5.3.17 via the gourl parameter to member/login.php.

    Last Modified: Apr 20, 2025
    Published: Jul 28, 2017
    Items Per Page
    Metinfo_Project Vulnerabilities & Security CVEs | CVE-DB