Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
MetInfo through 5.3.17 accepts the same CAPTCHA response for 120 seconds, which makes it easier for remote attackers to bypass intended challenge requirements by modifying the client-server data stream, as demonstrated by the login/findpass page.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MetInfo 安全漏洞
Vulnerability Description
MetInfo是中国米拓信息技术有限公司的一套使用PHP和Mysql开发的内容管理系统(CMS)。 MetInfo 5.3.17及之前的版本中存在安全漏洞。远程攻击者可通过更改客户端服务器之间的数据流利用该漏洞绕过captcha。
CVSS Information
N/A
Vulnerability Type
N/A