Authenticated Code Execution Vulnerability in MetInfo 5.3.17: Remote Attackers Can Generate Malicious PHP Scripts from Image Content

Authenticated Code Execution Vulnerability in MetInfo 5.3.17: Remote Attackers Can Generate Malicious PHP Scripts from Image Content

CVE-2017-11347 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

Authenticated Code Execution Vulnerability in MetInfo 5.3.17 allows a remote authenticated attacker to generate a PHP script with the content of a malicious image, related to admin/include/common.inc.php and admin/app/physical/physical.php.

Learn more about our Physical Security Assessment.