Vulnerabilities > Intelliants
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-07-19 | CVE-2017-11445 | SQL Injection vulnerability in Intelliants Subrion CMS Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array. | 9.8 |
2017-07-19 | CVE-2017-11444 | SQL Injection vulnerability in Intelliants Subrion CMS Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array. | 9.8 |
2017-07-02 | CVE-2017-10795 | Cross-site Scripting vulnerability in Intelliants Subrion 4.1.4 Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add/, a different vulnerability than CVE-2017-6069. | 6.1 |
2017-03-27 | CVE-2017-6069 | Cross-Site Request Forgery (CSRF) vulnerability in Intelliants Subrion CMS 4.0.5 Subrion CMS 4.0.5 has CSRF in admin/blog/add/. | 8.8 |
2017-03-27 | CVE-2017-6068 | Cross-Site Request Forgery (CSRF) vulnerability in Intelliants Subrion CMS 4.0.5 Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. | 8.8 |
2017-03-27 | CVE-2017-6066 | Cross-Site Request Forgery (CSRF) vulnerability in Intelliants Subrion CMS 4.0.5 Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. | 8.8 |
2017-03-27 | CVE-2017-6013 | SQL Injection vulnerability in Intelliants Subrion CMS 4.0.5.10 Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter. | 9.8 |
2017-03-27 | CVE-2017-6002 | Cross-Site Request Forgery (CSRF) vulnerability in Intelliants Subrion CMS 4.0.5.10 Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. | 8.8 |
2017-01-20 | CVE-2017-5543 | Code Injection vulnerability in Intelliants Subrion 4.0.5 includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request. | 9.8 |