Show filters
59 Total Results
Displaying 41-50 of 59
Sort by:
Attacker Value
Unknown
CVE-2018-14836
Disclosure Date: August 02, 2018 (last updated November 27, 2024)
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.
0
Attacker Value
Unknown
CVE-2017-15063
Disclosure Date: October 06, 2017 (last updated November 26, 2024)
There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to detect CSRF, it is called too late in the ia.core.php code, allowing (for example) an attack against the query parameter to panel/database.
0
Attacker Value
Unknown
CVE-2017-11445
Disclosure Date: July 19, 2017 (last updated November 26, 2024)
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
0
Attacker Value
Unknown
CVE-2017-11444
Disclosure Date: July 19, 2017 (last updated November 26, 2024)
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
0
Attacker Value
Unknown
CVE-2017-10795
Disclosure Date: July 02, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add/, a different vulnerability than CVE-2017-6069.
0
Attacker Value
Unknown
CVE-2017-6068
Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.
0
Attacker Value
Unknown
CVE-2017-6002
Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.
0
Attacker Value
Unknown
CVE-2017-6013
Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.
0
Attacker Value
Unknown
CVE-2017-6066
Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.
0
Attacker Value
Unknown
CVE-2017-6069
Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
0