Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-17431 |
|
Cross-Site Scripting (XSS) in genixcms (CVE-2017-17431)
cross-site scripting in genixcms (CVE-2017-17431). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-3933 |
|
SQL Injection in sqli (CVE-2015-3933)
SQL injection in sqli (CVE-2015-3933). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14765 |
|
In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a page=menus request.
In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a page=menus request.
|
| CVE-2017-14764 |
|
Code Injection in genixcms (CVE-2017-14764)
code injection in genixcms (CVE-2017-14764). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14762 |
|
In GeniXCMS 1.1.4, /inc/lib/Control/Backend/menus.control.php has XSS via the id parameter.
In GeniXCMS 1.1.4, /inc/lib/Control/Backend/menus.control.php has XSS via the id parameter.
|
| CVE-2017-14761 |
|
In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter.
In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter.
|
| CVE-2017-14231 |
|
Vulnerability in dos (CVE-2017-14231)
vulnerability in dos (CVE-2017-14231). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-8827 |
|
Authentication Bypass in dos (CVE-2017-8827)
authentication bypass in dos (CVE-2017-8827). Data can be tampered with by attackers.
|
| CVE-2017-8780 |
|
Cross-Site Scripting (XSS) in genixcms (CVE-2017-8780)
cross-site scripting in genixcms (CVE-2017-8780). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-8762 |
|
Cross-Site Scripting (XSS) in genixcms (CVE-2017-8762)
cross-site scripting in genixcms (CVE-2017-8762). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-8377 |
|
SQL Injection in sqli (CVE-2017-8377)
SQL injection in sqli (CVE-2017-8377). Successful exploitation can lead to full system takeover.
|
| CVE-2017-8376 |
|
Cross-Site Scripting (XSS) in genixcms (CVE-2017-8376)
cross-site scripting in genixcms (CVE-2017-8376). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-5959 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-5959)
vulnerability in csrf (CVE-2017-5959). Successful exploitation can lead to full system takeover.
|
| CVE-2017-6065 |
|
SQL Injection in sqli (CVE-2017-6065)
SQL injection in sqli (CVE-2017-6065). Successful exploitation can lead to full system takeover.
|
| CVE-2017-5575 |
|
SQL Injection in sqli (CVE-2017-5575)
SQL injection in sqli (CVE-2017-5575). Successful exploitation can lead to full system takeover.
|
| CVE-2017-5574 |
|
SQL Injection in sqli (CVE-2017-5574)
SQL injection in sqli (CVE-2017-5574). Successful exploitation can lead to full system takeover.
|
| CVE-2017-5515 |
|
Cross-Site Scripting (XSS) in metalgenix (CVE-2017-5515)
cross-site scripting in metalgenix (CVE-2017-5515). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-5520 |
|
Unrestricted File Upload in metalgenix (CVE-2017-5520)
vulnerability in metalgenix (CVE-2017-5520). Successful exploitation can lead to full system takeover.
|
| CVE-2017-5519 |
|
SQL Injection in sqli (CVE-2017-5519)
SQL injection in sqli (CVE-2017-5519). Successful exploitation can lead to full system takeover.
|
| CVE-2017-5518 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2017-5518)
SSRF in ssrf (CVE-2017-5518). Data can be tampered with by attackers.
|
| CVE-2017-5517 |
|
SQL Injection in sqli (CVE-2017-5517)
SQL injection in sqli (CVE-2017-5517). Successful exploitation can lead to full system takeover.
|
| CVE-2017-5516 |
|
Cross-Site Scripting (XSS) in metalgenix (CVE-2017-5516)
cross-site scripting in metalgenix (CVE-2017-5516). Risk of unauthorized operations or information disclosure.
|