MetInfo 5.3.17

CPE Details

MetInfo 5.3.17
5.3.17
2020-03-03
16h33 +00:00
2020-03-03
16h33 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:metinfo:metinfo:5.3.17:*:*:*:*:*:*:*

Informations

Vendor

metinfo

Product

metinfo

Version

5.3.17

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2017-14513 2017-09-17 19h00 +00:00 Directory traversal vulnerability in MetInfo 5.3.17 allows remote attackers to read information from any ini format file via the f_filename parameter in a fingerprintdo action to admin/app/physical/physical.php.
5.3
Medium
CVE-2017-11500 2017-07-20 22h00 +00:00 A directory traversal vulnerability exists in MetInfo 5.3.17. A remote attacker can use ..\ to delete any .zip file via the filenames parameter to /admin/system/database/filedown.php.
7.5
High
CVE-2017-9764 2017-07-19 10h00 +00:00 Cross-site scripting (XSS) vulnerability in MetInfo 5.3.17 allows remote attackers to inject arbitrary web script or HTML via the Client-IP or X-Forwarded-For HTTP header to /include/stat/stat.php in a para action.
6.1
Medium
CVE-2017-11347 2017-07-16 23h00 +00:00 Authenticated Code Execution Vulnerability in MetInfo 5.3.17 allows a remote authenticated attacker to generate a PHP script with the content of a malicious image, related to admin/include/common.inc.php and admin/app/physical/physical.php.
8.8
High