CVE-2015-3933

CRITICAL

MetalGenix GeniXCMS <0.0.3-patch - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-3933. PoCs published by cfreer.

AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in GenixCMS 0.0.3 via the 'email' and 'userid' parameters in register.php. The PoC includes HTTP requests with crafted payloads to trigger SQL errors and extract database information.

Description

Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php.

Exploits (1)

exploitdb WORKING POC
by cfreer · textwebappsphp
https://www.exploit-db.com/exploits/37363

This exploit demonstrates SQL injection vulnerabilities in GenixCMS 0.0.3 via the 'email' and 'userid' parameters in register.php. The PoC includes HTTP requests with crafted payloads to trigger SQL errors and extract database information.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: GenixCMS 0.0.3
No auth needed
Prerequisites: Access to the GenixCMS registration page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/37363/

Scores

CVSS v3 9.8
EPSS 0.0282
EPSS Percentile 86.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
genix/cms 0Packagist
metalgenix/genixcms < 0.0.3
Published Nov 08, 2017
Tracked Since Feb 18, 2026