Vendor CVEs
Metinfo
All CVEs
64 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-18296 | Med | 0.40 | 6.1 | 0.01 | Oct 15, 2018 | MetInfo 6.1.2 has XSS via the /admin/index.php bigclass parameter in an n=column&a=doadd action. | ||
| CVE-2018-9985 | Med | 0.40 | 6.1 | 0.01 | Apr 10, 2018 | The front page of MetInfo 6.0 allows XSS by sending a feedback message to an administrator. | ||
| CVE-2018-9928 | Med | 0.40 | 6.1 | 0.01 | Apr 10, 2018 | Cross-site scripting (XSS) vulnerability in save.php in MetInfo 6.0 allows remote attackers to inject arbitrary web script or HTML via the webname or weburl parameter. | ||
| CVE-2018-7721 | Med | 0.40 | 6.1 | 0.01 | Mar 7, 2018 | Cross Site Scripting (XSS) exists in MetInfo 6.0.0 via /feedback/index.php because app/system/feedback/web/feedback.class.php mishandles input data. | ||
| CVE-2017-11718 | Med | 0.40 | 6.1 | 0.01 | Jul 28, 2017 | There is URL Redirector Abuse in MetInfo through 5.3.17 via the gourl parameter to member/login.php. | ||
| CVE-2017-11716 | Med | 0.40 | 6.1 | 0.01 | Jul 28, 2017 | MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode. | ||
| CVE-2017-9764 | Med | 0.40 | 6.1 | 0.01 | Jul 19, 2017 | Cross-site scripting (XSS) vulnerability in MetInfo 5.3.17 allows remote attackers to inject arbitrary web script or HTML via the Client-IP or X-Forwarded-For HTTP header to /include/stat/stat.php in a para action. | ||
| CVE-2020-20600 | Med | 0.35 | 5.4 | 0.01 | Dec 22, 2021 | MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn. | ||
| CVE-2018-18374 | Med | 0.35 | 5.4 | 0.01 | Oct 16, 2018 | XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter. | ||
| CVE-2017-14513 | Med | 0.35 | 5.3 | 0.02 | Sep 17, 2017 | Directory traversal vulnerability in MetInfo 5.3.17 allows remote attackers to read information from any ini format file via the f_filename parameter in a fingerprintdo action to admin/app/physical/physical.php. | ||
| CVE-2017-6878 | Med | 0.35 | 5.4 | 0.01 | Mar 27, 2017 | Cross-site scripting (XSS) vulnerability in MetInfo 5.3.15 allows remote authenticated users to inject arbitrary web script or HTML via the name_2 parameter to admin/column/delete.php. | ||
| CVE-2018-17129 | Med | 0.32 | 4.9 | 0.01 | Sep 17, 2018 | MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field. | ||
| CVE-2018-14419 | Med | 0.31 | 4.8 | 0.01 | Jul 20, 2018 | MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page. | ||
| CVE-2010-4976 | 0.03 | — | 0.02 | Nov 1, 2011 | Cross-site scripting (XSS) vulnerability in search/search.php in MetInfo 3.0 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter (aka Search Box field). NOTE: some of these details are obtained from third party information. |
- risk 0.40cvss 6.1epss 0.01
MetInfo 6.1.2 has XSS via the /admin/index.php bigclass parameter in an n=column&a=doadd action.
- risk 0.40cvss 6.1epss 0.01
The front page of MetInfo 6.0 allows XSS by sending a feedback message to an administrator.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in save.php in MetInfo 6.0 allows remote attackers to inject arbitrary web script or HTML via the webname or weburl parameter.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) exists in MetInfo 6.0.0 via /feedback/index.php because app/system/feedback/web/feedback.class.php mishandles input data.
- risk 0.40cvss 6.1epss 0.01
There is URL Redirector Abuse in MetInfo through 5.3.17 via the gourl parameter to member/login.php.
- risk 0.40cvss 6.1epss 0.01
MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in MetInfo 5.3.17 allows remote attackers to inject arbitrary web script or HTML via the Client-IP or X-Forwarded-For HTTP header to /include/stat/stat.php in a para action.
- risk 0.35cvss 5.4epss 0.01
MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn.
- risk 0.35cvss 5.4epss 0.01
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.
- risk 0.35cvss 5.3epss 0.02
Directory traversal vulnerability in MetInfo 5.3.17 allows remote attackers to read information from any ini format file via the f_filename parameter in a fingerprintdo action to admin/app/physical/physical.php.
- risk 0.35cvss 5.4epss 0.01
Cross-site scripting (XSS) vulnerability in MetInfo 5.3.15 allows remote authenticated users to inject arbitrary web script or HTML via the name_2 parameter to admin/column/delete.php.
- risk 0.32cvss 4.9epss 0.01
MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field.
- risk 0.31cvss 4.8epss 0.01
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.
- CVE-2010-4976Nov 1, 2011risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in search/search.php in MetInfo 3.0 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter (aka Search Box field). NOTE: some of these details are obtained from third party information.
Page 2 of 2