Show filters
35 Total Results
Displaying 21-30 of 35
Sort by:
Attacker Value
Unknown

CVE-2018-14836

Disclosure Date: August 02, 2018 (last updated November 27, 2024)
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.
0
Attacker Value
Unknown

CVE-2017-11445

Disclosure Date: July 19, 2017 (last updated November 26, 2024)
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
0
Attacker Value
Unknown

CVE-2017-11444

Disclosure Date: July 19, 2017 (last updated November 26, 2024)
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
0
Attacker Value
Unknown

CVE-2017-6068

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.
0
Attacker Value
Unknown

CVE-2017-6002

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.
0
Attacker Value
Unknown

CVE-2017-6013

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.
0
Attacker Value
Unknown

CVE-2017-6066

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.
0
Attacker Value
Unknown

CVE-2017-6069

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
0
Attacker Value
Unknown

CVE-2015-4129

Disclosure Date: July 05, 2015 (last updated October 05, 2023)
SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via modified serialized data in a salt cookie.
0
Attacker Value
Unknown

CVE-2012-4771

Disclosure Date: October 22, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/accounts/, (2) admin/manage/, or (3) admin/manage/blocks/edit/; or (4) group parameter to admin/configuration/. NOTE: The f[accounts][fullname] and f[accounts][username] vectors are covered in CVE-2012-5452.
0