Vulnerability Description
Authenticated Code Execution Vulnerability in MetInfo 5.3.17 allows a remote authenticated attacker to generate a PHP script with the content of a malicious image, related to admin/include/common.inc.php and admin/app/physical/physical.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Metinfo | Metinfo | 5.3.17 |
References
- https://github.com/imp0wd3r/MetInfo_Vuln/blob/master/README.mdBroken Link
- https://github.com/imp0wd3r/MetInfo_Vuln/blob/master/README.mdBroken Link
FAQ
What is CVE-2017-11347?
CVE-2017-11347 is a vulnerability with a CVSS score of 8.8 (HIGH). Authenticated Code Execution Vulnerability in MetInfo 5.3.17 allows a remote authenticated attacker to generate a PHP script with the content of a malicious image, related to admin/include/common.inc....
How severe is CVE-2017-11347?
CVE-2017-11347 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11347?
Check the references section above for vendor advisories and patch information. Affected products include: Metinfo Metinfo.