Перейти к содержимому
Noroxi

Записи genixcms

18 опубликованных записей вендора genixcms.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
50 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

18 записей
  • CVE-2017-8827
    36Наблюдать

    forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) o

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    genixcms · genixcms8 мая 2017 г.

  • CVE-2017-14764
    35Наблюдать

    In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    genixcms · genixcms27 сент. 2017 г.

  • CVE-2017-8377
    35Наблюдать

    GeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    genixcms · genixcms1 мая 2017 г.

  • CVE-2017-14763
    35Наблюдать

    In the Install Themes page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    genixcms · genixcms27 сент. 2017 г.

  • CVE-2015-2679
    32Наблюдать

    Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL commands via the

    ВысокаяCVSS 7,5Proof of conceptEPSS 6 %

    genixcms · genixcms23 мар. 2015 г.

  • CVE-2016-10096
    29Наблюдать

    SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activ

    ВысокаяCVSS 7,3Эксплойта нетEPSS 2 %

    genixcms · genixcms1 янв. 2017 г.

  • CVE-2017-5346
    28Наблюдать

    SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to exe

    ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %

    genixcms · genixcms12 янв. 2017 г.

  • CVE-2017-14765
    24Наблюдать

    In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a page=menus request.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    genixcms · genixcms27 сент. 2017 г.

  • CVE-2017-14761
    24Наблюдать

    In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    genixcms · genixcms27 сент. 2017 г.

  • CVE-2017-14762
    24Наблюдать

    In GeniXCMS 1.1.4, /inc/lib/Control/Backend/menus.control.php has XSS via the id parameter.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    genixcms · genixcms27 сент. 2017 г.

  • CVE-2017-17431
    24Наблюдать

    GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    genixcms · genixcms5 дек. 2017 г.

  • CVE-2017-8388
    21Наблюдать

    GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1

    СредняяCVSS 5,3Эксплойта нетEPSS 2 %

    genixcms · genixcms1 мая 2017 г.

  • CVE-2017-14231
    21Наблюдать

    GeniXCMS before 1.1.0 allows remote attackers to cause a denial of service (account blockage) by leveraging the mishandling of certain usern

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    genixcms · genixcms10 сент. 2017 г.

  • CVE-2017-8376
    21Наблюдать

    GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    genixcms · genixcms1 мая 2017 г.

  • CVE-2017-8762
    21Наблюдать

    GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element.

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    genixcms · genixcms3 мая 2017 г.

  • CVE-2015-2678
    19Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web scrip

    СредняяCVSS 4,3Proof of conceptEPSS 5 %

    genixcms · genixcms23 мар. 2015 г.

  • CVE-2017-14740
    19Наблюдать

    Cross-site scripting (XSS) vulnerability in GeniXCMS 1.1.0 allows remote authenticated users to inject arbitrary web script or HTML via the

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    genixcms · genixcms26 апр. 2018 г.

  • CVE-2017-8780
    19Наблюдать

    GeniXCMS 1.0.2 has XSS triggered by a comment that is mishandled during a publish operation by an administrator, as demonstrated by a malfor

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    genixcms · genixcms4 мая 2017 г.