Show filters
275 Total Results
Displaying 181-190 of 275
Sort by:
Attacker Value
Unknown

CVE-2018-14476

Disclosure Date: April 04, 2018 (last updated November 27, 2024)
GeniXCMS 1.1.5 has XSS via the dbuser or dbhost parameter during step 1 of installation.
Attacker Value
Unknown

CVE-2015-3933

Disclosure Date: November 08, 2017 (last updated November 26, 2024)
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php.
0
Attacker Value
Unknown

CVE-2014-3930

Disclosure Date: April 03, 2017 (last updated November 26, 2024)
lg.pl in Cistron-LG 1.01 stores sensitive information under the web root with insufficient access controls, which allows remote attackers to obtain IP addresses and other unspecified router credentials.
0
Attacker Value
Unknown

CVE-2014-3928

Disclosure Date: April 03, 2017 (last updated November 26, 2024)
Cougar-LG stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials.
0
Attacker Value
Unknown

CVE-2014-3929

Disclosure Date: April 03, 2017 (last updated November 26, 2024)
The default configuration for Cougar-LG stores sensitive information under the web root with insufficient access control, which might allow remote attackers to obtain private ssh keys.
0
Attacker Value
Unknown

CVE-2014-3927

Disclosure Date: April 03, 2017 (last updated November 26, 2024)
mrlg-lib.php in mrlg4php before 1.0.8 allows remote attackers to execute arbitrary shell code.
0
Attacker Value
Unknown

CVE-2014-3926

Disclosure Date: March 13, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in lg.cgi in Cougar LG 1.9 allows remote attackers to inject arbitrary web script or HTML via the "addr" parameter.
0
Attacker Value
Unknown

CVE-2017-5959

Disclosure Date: February 21, 2017 (last updated November 26, 2024)
CSRF token bypass in GeniXCMS before 1.0.2 could result in escalation of privileges. The forgotpassword.php page can be used to acquire a token.
0
Attacker Value
Unknown

CVE-2017-6065

Disclosure Date: February 17, 2017 (last updated November 26, 2024)
SQL injection vulnerability in inc/lib/Control/Backend/menus.control.php in GeniXCMS through 1.0.2 allows remote authenticated users to execute arbitrary SQL commands via the order parameter.
0
Attacker Value
Unknown

CVE-2017-5574

Disclosure Date: January 23, 2017 (last updated November 25, 2024)
SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows unauthenticated users to execute arbitrary SQL commands via the activation parameter.
0