CVE-2015-5066
Last modified
CVE-2015-5066 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) content or (2) title field in an add action in the posts page to index.php or the (3) q parameter in the posts page to index.php.. EPSS estimates a 3.76% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) content or (2) title field in an add action in the posts page to index.php or the (3) q parameter in the posts page to index.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Metalgenix | Genixcms | 0.0.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-5066?
How severe is CVE-2015-5066?
How do I fix CVE-2015-5066?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-5060Cross-site scripting (XSS) vulnerability in anchor-cms befor…
- CVE-2015-5061Cross-site scripting (XSS) vulnerability in Zoho ManageEngin…
- CVE-2015-5062Open redirect vulnerability in SilverStripe CMS & Framework …
- CVE-2015-5063Multiple cross-site scripting (XSS) vulnerabilities in Silve…
- CVE-2015-5064Multiple cross-site scripting (XSS) vulnerabilities in MySql…
- CVE-2015-5065Absolute path traversal vulnerability in proxy.php in the go…
- CVE-2015-5067The (1) Cross-System Tools and (2) Data Transfer Workbench i…
- CVE-2015-5068XML external entity (XXE) vulnerability in SAP Mobile Platfo…
- CVE-2015-5069The (1) filesystem::get_wml_location function in filesystem.…
- CVE-2015-5070The (1) filesystem::get_wml_location function in filesystem.…
- CVE-2015-5071AR System Mid Tier in the AR System Mid Tier component befor…6.5
- CVE-2015-5072The BIRT Engine servlet in the AR System Mid Tier component …6.5
Are you affected by CVE-2015-5066?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
