Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2017-8762
Disclosure Date: May 03, 2017 (last updated November 26, 2024)
GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element.
0
Attacker Value
Unknown
CVE-2017-8376
Disclosure Date: May 01, 2017 (last updated November 26, 2024)
GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.
0
Attacker Value
Unknown
CVE-2017-8388
Disclosure Date: May 01, 2017 (last updated November 26, 2024)
GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1 request.
0
Attacker Value
Unknown
CVE-2017-8377
Disclosure Date: May 01, 2017 (last updated November 26, 2024)
GeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.
0
Attacker Value
Unknown
CVE-2017-5346
Disclosure Date: January 12, 2017 (last updated November 25, 2024)
SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.
0
Attacker Value
Unknown
CVE-2016-10096
Disclosure Date: January 01, 2017 (last updated November 25, 2024)
SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activation parameter.
0
Attacker Value
Unknown
CVE-2015-2678
Disclosure Date: March 23, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter in the categories page to gxadmin/index.php or (2) page parameter to index.php.
0
Attacker Value
Unknown
CVE-2015-2679
Disclosure Date: March 23, 2015 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php or (2) username parameter to gxadmin/login.php.
0