Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
genixcms genixcms 0.0.8 vulnerabilities and exploits
(subscribe to this query)
578
VMScore
CVE-2017-5346
SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.
Genixcms Genixcms 0.0.8
578
VMScore
CVE-2017-5347
SQL injection vulnerability in inc/mod/newsletter/options.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the recipient parameter to gxadmin/index.php.
Metalgenix Genixcms 0.0.8
578
VMScore
CVE-2017-5345
SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default URI.
Metalgenix Genixcms 0.0.8
668
VMScore
CVE-2017-5517
SQL injection vulnerability in author.control.php in GeniXCMS up to and including 0.0.8 allows remote malicious users to execute arbitrary SQL commands via the type parameter.
Metalgenix Genixcms
668
VMScore
CVE-2017-5519
SQL injection vulnerability in Posts.class.php in GeniXCMS up to and including 0.0.8 allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Metalgenix Genixcms
383
VMScore
CVE-2017-5516
Multiple cross-site scripting (XSS) vulnerabilities in the user forms in GeniXCMS up to and including 0.0.8 allow remote malicious users to inject arbitrary web script or HTML via crafted parameters.
Metalgenix Genixcms
312
VMScore
CVE-2017-5515
Cross-site scripting (XSS) vulnerability in the user prompt function in GeniXCMS up to and including 0.0.8 allows remote authenticated users to inject arbitrary web script or HTML via tag names.
Metalgenix Genixcms
383
VMScore
CVE-2017-5518
The media-file upload feature in GeniXCMS up to and including 0.0.8 allows remote malicious users to conduct SSRF attacks via a URL, as demonstrated by a URL with an intranet IP address.
Metalgenix Genixcms
578
VMScore
CVE-2017-5520
The media rename feature in GeniXCMS up to and including 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to rename and execute files with the `.php6`, `.php7` and `.phtml` extensions.
Metalgenix Genixcms
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started