MetInfo CMS是中国米拓(MetInfo)公司的一个内容管理系统。 MetInfo CMS 7.9版本、8.0版本和8.1版本存在安全漏洞,该漏洞源于未经验证的PHP代码注入,可能导致远程攻击者通过发送包含恶意PHP代码的特制请求来执行任意代码,从而完全控制受影响的服务器。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MetInfo CMS | MetInfo CMS | 7.9.0≤ 8.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MetInfo CMS | MetInfo CMS | 7.9.0 ~ 8.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | MetInfo CMS 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability caused by insufficient input neutralization in the execution path, letting remote attackers execute arbitrary code remotely, exploit requires crafted requests. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-29014.yaml | POC Details |
No comments yet