Show filters
290 Total Results
Displaying 91-100 of 290
Sort by:
Attacker Value
Unknown
CVE-2017-5520
Disclosure Date: January 17, 2017 (last updated November 25, 2024)
The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to rename and execute files with the `.php6`, `.php7` and `.phtml` extensions.
0
Attacker Value
Unknown
CVE-2017-5519
Disclosure Date: January 17, 2017 (last updated November 25, 2024)
SQL injection vulnerability in Posts.class.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2017-5347
Disclosure Date: January 12, 2017 (last updated November 25, 2024)
SQL injection vulnerability in inc/mod/newsletter/options.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the recipient parameter to gxadmin/index.php.
0
Attacker Value
Unknown
CVE-2017-5345
Disclosure Date: January 12, 2017 (last updated November 25, 2024)
SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default URI.
0
Attacker Value
Unknown
CVE-2017-5346
Disclosure Date: January 12, 2017 (last updated November 25, 2024)
SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.
0
Attacker Value
Unknown
CVE-2016-10096
Disclosure Date: January 01, 2017 (last updated November 25, 2024)
SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activation parameter.
0
Attacker Value
Unknown
CVE-2015-5066
Disclosure Date: June 24, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) content or (2) title field in an add action in the posts page to index.php or the (3) q parameter in the posts page to index.php.
0
Attacker Value
Unknown
CVE-2015-2680
Disclosure Date: March 23, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a request in the users page to gxadmin/index.php.
0
Attacker Value
Unknown
CVE-2015-2678
Disclosure Date: March 23, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter in the categories page to gxadmin/index.php or (2) page parameter to index.php.
0
Attacker Value
Unknown
CVE-2015-2679
Disclosure Date: March 23, 2015 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php or (2) username parameter to gxadmin/login.php.
0