Vulnerability Description
Metinfo v6.0.0 allows remote attackers to write code into a .php file, and execute that code, via the module parameter to admin/column/save.php in an editor upload action.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Metinfo | Metinfo | 6.0.0 |
Related Weaknesses (CWE)
References
- http://www.kingkk.com/2018/06/Metinfo-v6-0-0-getshell-in-background/ExploitThird Party Advisory
- http://www.kingkk.com/2018/06/Metinfo-v6-0-0-getshell-in-background/ExploitThird Party Advisory
FAQ
What is CVE-2018-13024?
CVE-2018-13024 is a vulnerability with a CVSS score of 7.2 (HIGH). Metinfo v6.0.0 allows remote attackers to write code into a .php file, and execute that code, via the module parameter to admin/column/save.php in an editor upload action.
How severe is CVE-2018-13024?
CVE-2018-13024 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-13024?
Check the references section above for vendor advisories and patch information. Affected products include: Metinfo Metinfo.