Known Vulnerabilities for products from Gxlcms
Listed below are 15 of the newest known vulnerabilities associated with the vendor "Gxlcms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-20975 json | In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter. | 9.8 - CRITICAL | 2021-08-12 | 2021-08-20 |
| CVE-2018-18488 json | In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter. | 9.8 - CRITICAL | 2018-10-18 | 2018-11-30 |
| CVE-2018-18487 json | In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, the database backup filename generation uses mt_rand() unsafely, re... | 7.5 - HIGH | 2018-10-18 | 2018-11-30 |
| CVE-2018-16655 json | Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php. | 6.1 - MEDIUM | 2018-09-07 | 2018-11-09 |
| CVE-2018-16437 json | Gxlcms 2.0 before bug fix 20180915 has Directory Traversal exploitable by an administrator. | 4.9 - MEDIUM | 2018-09-05 | 2018-11-05 |
| CVE-2018-16436 json | Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator. | 7.2 - HIGH | 2018-09-05 | 2018-11-05 |
| CVE-2018-15177 json | In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account. | 8.8 - HIGH | 2018-08-08 | 2018-10-05 |
| CVE-2018-14685 json | The add function in www/Lib/Lib/Action/Admin/TplAction.class.php in Gxlcms v1.1.4 allows remote attackers to read arbitrary f... | 9.8 - CRITICAL | 2018-07-28 | 2018-09-28 |
| CVE-2018-9852 json | In Gxlcms QY v1.0.0713, Lib\Lib\Action\Home\HitsAction.class.php allows remote attackers to read data from a database by embe... | 9.8 - CRITICAL | 2018-04-08 | 2020-01-30 |
| CVE-2018-9851 json | In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to read any file via a modified path... | 7.5 - HIGH | 2018-04-08 | 2018-05-17 |
| CVE-2018-9850 json | In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory tr... | 7.5 - HIGH | 2018-04-08 | 2018-05-14 |
| CVE-2018-9848 json | In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to execute... | 9.8 - CRITICAL | 2018-04-07 | 2018-05-14 |
| CVE-2018-9847 json | In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute ar... | 9.8 - CRITICAL | 2018-04-07 | 2018-05-14 |
| CVE-2018-9247 json | The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execute ar... | 9.8 - CRITICAL | 2018-04-04 | 2018-05-09 |
| CVE-2017-14979 json | Gxlcms uses an unsafe character-replacement approach in an attempt to restrict access, which allows remote attackers to read ... | 7.5 - HIGH | 2017-10-03 | 2019-10-03 |