Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2022-24563

Disclosure Date: March 03, 2022 (last updated February 23, 2025)
In Genixcms v1.1.11, a stored Cross-Site Scripting (XSS) vulnerability exists in /gxadmin/index.php?page=themes&view=options" via the intro_title and intro_image parameters.
Attacker Value
Unknown

CVE-2020-10057

Disclosure Date: March 04, 2020 (last updated February 21, 2025)
GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection mechanism, but without validation that "token" is associated with an administrative user.
Attacker Value
Unknown

CVE-2018-14476

Disclosure Date: April 04, 2018 (last updated November 27, 2024)
GeniXCMS 1.1.5 has XSS via the dbuser or dbhost parameter during step 1 of installation.
Attacker Value
Unknown

CVE-2015-3933

Disclosure Date: November 08, 2017 (last updated November 26, 2024)
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php.
0
Attacker Value
Unknown

CVE-2017-5959

Disclosure Date: February 21, 2017 (last updated November 26, 2024)
CSRF token bypass in GeniXCMS before 1.0.2 could result in escalation of privileges. The forgotpassword.php page can be used to acquire a token.
0
Attacker Value
Unknown

CVE-2017-6065

Disclosure Date: February 17, 2017 (last updated November 26, 2024)
SQL injection vulnerability in inc/lib/Control/Backend/menus.control.php in GeniXCMS through 1.0.2 allows remote authenticated users to execute arbitrary SQL commands via the order parameter.
0
Attacker Value
Unknown

CVE-2017-5574

Disclosure Date: January 23, 2017 (last updated November 25, 2024)
SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows unauthenticated users to execute arbitrary SQL commands via the activation parameter.
0
Attacker Value
Unknown

CVE-2017-5575

Disclosure Date: January 23, 2017 (last updated November 25, 2024)
SQL injection vulnerability in inc/lib/Options.class.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the modules parameter.
0
Attacker Value
Unknown

CVE-2017-5515

Disclosure Date: January 17, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the user prompt function in GeniXCMS through 0.0.8 allows remote authenticated users to inject arbitrary web script or HTML via tag names.
0
Attacker Value
Unknown

CVE-2017-5516

Disclosure Date: January 17, 2017 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the user forms in GeniXCMS through 0.0.8 allow remote attackers to inject arbitrary web script or HTML via crafted parameters.
0