Vulnerabilities
Vulnerable Software
Intelliants:  >> Subrion Cms  Security Vulnerabilities
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
CVSS Score
9.8
EPSS Score
0.786
Published
2017-07-19
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
CVSS Score
9.8
EPSS Score
0.003
Published
2017-07-19
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.
CVSS Score
8.8
EPSS Score
0.001
Published
2017-03-27
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.
CVSS Score
9.8
EPSS Score
0.006
Published
2017-03-27
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.
CVSS Score
8.8
EPSS Score
0.002
Published
2017-03-27
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.
CVSS Score
8.8
EPSS Score
0.002
Published
2017-03-27
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
CVSS Score
8.8
EPSS Score
0.002
Published
2017-03-27
SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via modified serialized data in a salt cookie.
CVSS Score
6.5
EPSS Score
0.009
Published
2015-07-05
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) multi_title parameter to blocks/add/; (2) cost, (3) days, or (4) title[en] parameter to plans/add/; (5) name or (6) title[en] parameter to fields/group/add/ in admin/manage/; or (7) f[accounts][fullname] or (8) f[accounts][username] parameter to advsearch/. NOTE: This might overlap CVE-2011-5211. NOTE: it was later reported that the f[accounts][fullname] and f[accounts][username] vectors might also affect 2.2.2.
CVSS Score
4.3
EPSS Score
0.131
Published
2012-10-22
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/accounts/, (2) admin/manage/, or (3) admin/manage/blocks/edit/; or (4) group parameter to admin/configuration/. NOTE: The f[accounts][fullname] and f[accounts][username] vectors are covered in CVE-2012-5452.
CVSS Score
4.3
EPSS Score
0.078
Published
2012-10-22


Contact Us

Shodan ® - All rights reserved