Metinfo v6.0.0 allows remote malicious users to write code into a .php file, and execute that code, via the module parameter to admin/column/save.php in an editor upload action.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
metinfo metinfo 6.0.0 |