Show filters
59 Total Results
Displaying 41-50 of 59
Sort by:
Attacker Value
Unknown

CVE-2018-14836

Disclosure Date: August 02, 2018 (last updated November 27, 2024)
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.
0
Attacker Value
Unknown

CVE-2017-15063

Disclosure Date: October 06, 2017 (last updated November 26, 2024)
There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to detect CSRF, it is called too late in the ia.core.php code, allowing (for example) an attack against the query parameter to panel/database.
0
Attacker Value
Unknown

CVE-2017-11445

Disclosure Date: July 19, 2017 (last updated November 26, 2024)
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
0
Attacker Value
Unknown

CVE-2017-11444

Disclosure Date: July 19, 2017 (last updated November 26, 2024)
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
0
Attacker Value
Unknown

CVE-2017-10795

Disclosure Date: July 02, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add/, a different vulnerability than CVE-2017-6069.
0
Attacker Value
Unknown

CVE-2017-6068

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.
0
Attacker Value
Unknown

CVE-2017-6002

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.
0
Attacker Value
Unknown

CVE-2017-6013

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.
0
Attacker Value
Unknown

CVE-2017-6066

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.
0
Attacker Value
Unknown

CVE-2017-6069

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
0