Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-20975 In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter. Gxlcms No fix yet Fix from $2,3002021-08-12 CRITICAL 9.8 CVE-2018-18488 In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter. Gxlcms No fix yet Fix from $2,3002018-10-18 HIGH 7.5 CVE-2018-18487 In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, the database backup filename generation uses mt_rand() unsafely, resulting in predictable d… Gxlcms No fix yet Fix from $1,9502018-10-18 MEDIUM 6.1 CVE-2018-16655 Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php. Gxlcms No fix yet Fix from $1,6002018-09-07 HIGH 7.2 CVE-2018-16436 Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator. Gxlcms No fix yet Fix from $1,9502018-09-05 HIGH 8.8 CVE-2018-15177 In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account. Gxlcms Mitigation only Fix from $1,9502018-08-08 CRITICAL 9.8 CVE-2018-14685 The add function in www/Lib/Lib/Action/Admin/TplAction.class.php in Gxlcms v1.1.4 allows remote attackers to read arbitrary files via a crafted index… Gxlcms No fix yet Fix from $2,3002018-07-28 CRITICAL 9.8 CVE-2018-9852 In Gxlcms QY v1.0.0713, Lib\Lib\Action\Home\HitsAction.class.php allows remote attackers to read data from a database by embedding a FROM clause in a… Gxlcms Qy No fix yet Fix from $2,3002018-04-08 HIGH 7.5 CVE-2018-9850 In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the… Gxlcms Qy No fix yet Fix from $1,9502018-04-08 HIGH 7.5 CVE-2018-9851 In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to read any file via a modified pathname in an Admin-Tpl req… Gxlcms Qy No fix yet Fix from $1,9502018-04-08 CRITICAL 9.8 CVE-2018-9847 In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute arbitrary PHP code by plac… Gxlcms Qy No fix yet Fix from $2,3002018-04-07 CRITICAL 9.8 CVE-2018-9848 In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to execute arbitrary PHP code by f… Gxlcms Qy No fix yet Fix from $2,3002018-04-07 CRITICAL 9.8 CVE-2018-9247 The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execute arbitrary SQL statements v… Gxlcms Qy No fix yet Fix from $2,3002018-04-04 HIGH 7.5 CVE-2017-14979 Gxlcms uses an unsafe character-replacement approach in an attempt to restrict access, which allows remote attackers to read arbitrary files via modi… Gxlcms No fix yet Fix from $1,9502017-10-03