CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102340 | CVE-2017-5520 | Candidate | The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to rename and execute files with the `.php6`, `.php7` and `.phtml` extensions. | Assigned (20170117) | None (candidate not yet proposed) | View | |
102339 | CVE-2017-5519 | Candidate | SQL injection vulnerability in Posts.class.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20170117) | None (candidate not yet proposed) | View | |
102338 | CVE-2017-5518 | Candidate | The media-file upload feature in GeniXCMS through 0.0.8 allows remote attackers to conduct SSRF attacks via a URL, as demonstrated by a URL with an intranet IP address. | Assigned (20170117) | None (candidate not yet proposed) | View | |
102337 | CVE-2017-5517 | Candidate | SQL injection vulnerability in author.control.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the type parameter. | Assigned (20170117) | None (candidate not yet proposed) | View | |
102336 | CVE-2017-5516 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in the user forms in GeniXCMS through 0.0.8 allow remote attackers to inject arbitrary web script or HTML via crafted parameters. | Assigned (20170117) | None (candidate not yet proposed) | View |
Page 476 of 20943, showing 5 records out of 104715 total, starting on record 2376, ending on 2380