9.8
CVSSv3

CVE-2015-3933

Published: 08/11/2017 Updated: 28/11/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS prior to 0.0.3-patch allow remote malicious users to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php.

Vulnerable Product Search on Vulmon Subscribe to Product

metalgenix genixcms

Exploits

# Exploit Title: Genixcms registerphp multiple SQL vuln # Date: 2015-06-23 # Exploit Author: cfreer (poc-lab) # Vendor Homepage: wwwgenixcmsorg # Software Link: codeloadgithubcom/semplon/GeniXCMS/zip/master/GeniXCMS-masterzip # Version: 003 # Tested on: Apache/247 (Win32) # CVE : CVE-2015-3933 ===================== SOFT ...
GeniXCMS version 003 suffers from multiple remote SQL injection vulnerabilities ...