Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in MetInfo 6.0.0. In install/install.php in the installation process, the config/config_db.php configuration file filtering is not rigorous: one can insert malicious code in the installation process to execute arbitrary commands or obtain a web shell.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MetInfo 安全漏洞
Vulnerability Description
MetInfo是中国米拓信息技术有限公司的一套使用PHP和Mysql开发的内容管理系统(CMS)。 MetInfo 6.0.0版本中存在安全漏洞,该漏洞源于config/config_db.php文件的配置文件的过滤不严谨。攻击者可利用该漏洞注入恶意的代码,执行任意命令或获取Web shell。
CVSS Information
N/A
Vulnerability Type
N/A