Vulnerabilities
Vulnerable Software
Intelliants:  >> Subrion Cms  Security Vulnerabilities
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-12-04
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.
CVSS Score
7.2
EPSS Score
0.86
Published
2018-11-21
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
CVSS Score
9.8
EPSS Score
0.793
Published
2017-07-19
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
CVSS Score
9.8
EPSS Score
0.003
Published
2017-07-19
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.
CVSS Score
8.8
EPSS Score
0.001
Published
2017-03-27
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.
CVSS Score
9.8
EPSS Score
0.006
Published
2017-03-27
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.
CVSS Score
8.8
EPSS Score
0.002
Published
2017-03-27
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.
CVSS Score
8.8
EPSS Score
0.002
Published
2017-03-27
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
CVSS Score
8.8
EPSS Score
0.002
Published
2017-03-27
SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via modified serialized data in a salt cookie.
CVSS Score
6.5
EPSS Score
0.008
Published
2015-07-05


Contact Us

Shodan ® - All rights reserved