Show filters
61 Total Results
Displaying 41-50 of 61
Sort by:
Attacker Value
Unknown

CVE-2017-11445

Disclosure Date: July 19, 2017 (last updated November 26, 2024)
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
0
Attacker Value
Unknown

CVE-2017-11444

Disclosure Date: July 19, 2017 (last updated November 26, 2024)
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
0
Attacker Value
Unknown

CVE-2017-10795

Disclosure Date: July 02, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add/, a different vulnerability than CVE-2017-6069.
0
Attacker Value
Unknown

CVE-2017-6068

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.
0
Attacker Value
Unknown

CVE-2017-6002

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.
0
Attacker Value
Unknown

CVE-2017-6013

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.
0
Attacker Value
Unknown

CVE-2017-6066

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.
0
Attacker Value
Unknown

CVE-2017-6069

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
0
Attacker Value
Unknown

CVE-2017-5543

Disclosure Date: January 20, 2017 (last updated November 25, 2024)
includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.
0
Attacker Value
Unknown

CVE-2015-4129

Disclosure Date: July 05, 2015 (last updated October 05, 2023)
SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via modified serialized data in a salt cookie.
0