VYPR

Vendor CVEs

Metinfo

All CVEs

64 total · sorted by risk
  • CVE-2018-18296MedOct 15, 2018
    risk 0.40cvss 6.1epss 0.01

    MetInfo 6.1.2 has XSS via the /admin/index.php bigclass parameter in an n=column&a=doadd action.

  • CVE-2018-9985MedApr 10, 2018
    risk 0.40cvss 6.1epss 0.01

    The front page of MetInfo 6.0 allows XSS by sending a feedback message to an administrator.

  • CVE-2018-9928MedApr 10, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in save.php in MetInfo 6.0 allows remote attackers to inject arbitrary web script or HTML via the webname or weburl parameter.

  • CVE-2018-7721MedMar 7, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) exists in MetInfo 6.0.0 via /feedback/index.php because app/system/feedback/web/feedback.class.php mishandles input data.

  • CVE-2017-11718MedJul 28, 2017
    risk 0.40cvss 6.1epss 0.01

    There is URL Redirector Abuse in MetInfo through 5.3.17 via the gourl parameter to member/login.php.

  • CVE-2017-11716MedJul 28, 2017
    risk 0.40cvss 6.1epss 0.01

    MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode.

  • CVE-2017-9764MedJul 19, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in MetInfo 5.3.17 allows remote attackers to inject arbitrary web script or HTML via the Client-IP or X-Forwarded-For HTTP header to /include/stat/stat.php in a para action.

  • CVE-2020-20600MedDec 22, 2021
    risk 0.35cvss 5.4epss 0.01

    MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn.

  • CVE-2018-18374MedOct 16, 2018
    risk 0.35cvss 5.4epss 0.01

    XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.

  • CVE-2017-14513MedSep 17, 2017
    risk 0.35cvss 5.3epss 0.02

    Directory traversal vulnerability in MetInfo 5.3.17 allows remote attackers to read information from any ini format file via the f_filename parameter in a fingerprintdo action to admin/app/physical/physical.php.

  • CVE-2017-6878MedMar 27, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in MetInfo 5.3.15 allows remote authenticated users to inject arbitrary web script or HTML via the name_2 parameter to admin/column/delete.php.

  • CVE-2018-17129MedSep 17, 2018
    risk 0.32cvss 4.9epss 0.01

    MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field.

  • CVE-2018-14419MedJul 20, 2018
    risk 0.31cvss 4.8epss 0.01

    MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.

  • CVE-2010-4976Nov 1, 2011
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in search/search.php in MetInfo 3.0 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter (aka Search Box field). NOTE: some of these details are obtained from third party information.

Page 2 of 2