CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102340  CVE-2017-5520  Candidate  The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to rename and execute files with the `.php6`, `.php7` and `.phtml` extensions.  Assigned (20170117)  None (candidate not yet proposed)    View
102339  CVE-2017-5519  Candidate  SQL injection vulnerability in Posts.class.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20170117)  None (candidate not yet proposed)    View
102338  CVE-2017-5518  Candidate  The media-file upload feature in GeniXCMS through 0.0.8 allows remote attackers to conduct SSRF attacks via a URL, as demonstrated by a URL with an intranet IP address.  Assigned (20170117)  None (candidate not yet proposed)    View
102337  CVE-2017-5517  Candidate  SQL injection vulnerability in author.control.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the type parameter.  Assigned (20170117)  None (candidate not yet proposed)    View
102336  CVE-2017-5516  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the user forms in GeniXCMS through 0.0.8 allow remote attackers to inject arbitrary web script or HTML via crafted parameters.  Assigned (20170117)  None (candidate not yet proposed)    View

Page 476 of 20943, showing 5 records out of 104715 total, starting on record 2376, ending on 2380

Actions