İçeriğe atla
Noroxi

genixcms kayıtları

genixcms üreticisine ait 18 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%50
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

18 kayıt
  • CVE-2017-8827
    36İzleyin

    forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) o

    KritikCVSS 9,1İstismar yokEPSS %2

    genixcms · genixcms8 May 2017

  • CVE-2017-14764
    35İzleyin

    In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of

    YüksekCVSS 8,8İstismar yokEPSS %2

    genixcms · genixcms27 Eyl 2017

  • CVE-2017-8377
    35İzleyin

    GeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.

    YüksekCVSS 8,8İstismar yokEPSS %1

    genixcms · genixcms1 May 2017

  • CVE-2017-14763
    35İzleyin

    In the Install Themes page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of

    YüksekCVSS 8,8İstismar yokEPSS %1

    genixcms · genixcms27 Eyl 2017

  • CVE-2015-2679
    32İzleyin

    Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL commands via the

    YüksekCVSS 7,5Kavram kanıtıEPSS %6

    genixcms · genixcms23 Mar 2015

  • CVE-2016-10096
    29İzleyin

    SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activ

    YüksekCVSS 7,3İstismar yokEPSS %2

    genixcms · genixcms1 Oca 2017

  • CVE-2017-5346
    28İzleyin

    SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to exe

    YüksekCVSS 7,2İstismar yokEPSS %2

    genixcms · genixcms12 Oca 2017

  • CVE-2017-14765
    24İzleyin

    In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a page=menus request.

    OrtaCVSS 6,1İstismar yokEPSS %1

    genixcms · genixcms27 Eyl 2017

  • CVE-2017-14761
    24İzleyin

    In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter.

    OrtaCVSS 6,1İstismar yokEPSS %1

    genixcms · genixcms27 Eyl 2017

  • CVE-2017-14762
    24İzleyin

    In GeniXCMS 1.1.4, /inc/lib/Control/Backend/menus.control.php has XSS via the id parameter.

    OrtaCVSS 6,1İstismar yokEPSS %1

    genixcms · genixcms27 Eyl 2017

  • CVE-2017-17431
    24İzleyin

    GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter.

    OrtaCVSS 6,1İstismar yokEPSS %1

    genixcms · genixcms5 Ara 2017

  • CVE-2017-8388
    21İzleyin

    GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1

    OrtaCVSS 5,3İstismar yokEPSS %2

    genixcms · genixcms1 May 2017

  • CVE-2017-14231
    21İzleyin

    GeniXCMS before 1.1.0 allows remote attackers to cause a denial of service (account blockage) by leveraging the mishandling of certain usern

    OrtaCVSS 5,3İstismar yokEPSS %1

    genixcms · genixcms10 Eyl 2017

  • CVE-2017-8376
    21İzleyin

    GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.

    OrtaCVSS 5,4İstismar yokEPSS %1

    genixcms · genixcms1 May 2017

  • CVE-2017-8762
    21İzleyin

    GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element.

    OrtaCVSS 5,4İstismar yokEPSS %0

    genixcms · genixcms3 May 2017

  • CVE-2015-2678
    19İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web scrip

    OrtaCVSS 4,3Kavram kanıtıEPSS %5

    genixcms · genixcms23 Mar 2015

  • CVE-2017-14740
    19İzleyin

    Cross-site scripting (XSS) vulnerability in GeniXCMS 1.1.0 allows remote authenticated users to inject arbitrary web script or HTML via the

    OrtaCVSS 4,8İstismar yokEPSS %1

    genixcms · genixcms26 Nis 2018

  • CVE-2017-8780
    19İzleyin

    GeniXCMS 1.0.2 has XSS triggered by a comment that is mishandled during a publish operation by an administrator, as demonstrated by a malfor

    OrtaCVSS 4,8İstismar yokEPSS %1

    genixcms · genixcms4 May 2017