Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
genixcms genixcms vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2017-5519
SQL injection vulnerability in Posts.class.php in GeniXCMS up to and including 0.0.8 allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Metalgenix Genixcms
668
VMScore
CVE-2017-5575
SQL injection vulnerability in inc/lib/Options.class.php in GeniXCMS prior to 1.0.0 allows remote malicious users to execute arbitrary SQL commands via the modules parameter.
Metalgenix Genixcms
685
VMScore
CVE-2015-2680
Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS prior to 0.0.2 allows remote malicious users to hijack the authentication of administrators for requests that add an administrator account via a request in the users page to gxadmin/index.php.
Metalgenix Genixcms
1 EDB exploit
668
VMScore
CVE-2017-5959
CSRF token bypass in GeniXCMS prior to 1.0.2 could result in escalation of privileges. The forgotpassword.php page can be used to acquire a token.
Metalgenix Genixcms
578
VMScore
CVE-2017-6065
SQL injection vulnerability in inc/lib/Control/Backend/menus.control.php in GeniXCMS up to and including 1.0.2 allows remote authenticated users to execute arbitrary SQL commands via the order parameter.
Metalgenix Genixcms
383
VMScore
CVE-2017-5516
Multiple cross-site scripting (XSS) vulnerabilities in the user forms in GeniXCMS up to and including 0.0.8 allow remote malicious users to inject arbitrary web script or HTML via crafted parameters.
Metalgenix Genixcms
383
VMScore
CVE-2017-5518
The media-file upload feature in GeniXCMS up to and including 0.0.8 allows remote malicious users to conduct SSRF attacks via a URL, as demonstrated by a URL with an intranet IP address.
Metalgenix Genixcms
578
VMScore
CVE-2017-5520
The media rename feature in GeniXCMS up to and including 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to rename and execute files with the `.php6`, `.php7` and `.phtml` extensions.
Metalgenix Genixcms
668
VMScore
CVE-2017-5574
SQL injection vulnerability in register.php in GeniXCMS prior to 1.0.0 allows unauthenticated users to execute arbitrary SQL commands via the activation parameter.
Metalgenix Genixcms
755
VMScore
CVE-2015-3933
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS prior to 0.0.3-patch allow remote malicious users to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php.
Metalgenix Genixcms
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »