Vulnerabilities > Intelliants > Subrion CMS > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-11-21 | CVE-2018-19422 | Unrestricted Upload of File with Dangerous Type vulnerability in Intelliants Subrion CMS 4.2.1 /panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these. | 7.2 |
2017-07-19 | CVE-2017-11445 | SQL Injection vulnerability in Intelliants Subrion CMS Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array. | 7.5 |
2017-07-19 | CVE-2017-11444 | SQL Injection vulnerability in Intelliants Subrion CMS Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array. | 7.5 |
2017-03-27 | CVE-2017-6013 | SQL Injection vulnerability in Intelliants Subrion CMS 4.0.5.10 Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter. | 7.5 |
2012-10-22 | CVE-2012-4772 | SQL Injection vulnerability in Intelliants Subrion CMS SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via the plan_id parameter. | 7.5 |
2012-10-22 | CVE-2011-5212 | SQL Injection vulnerability in Intelliants Subrion CMS 2.0.4 SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name or (2) password field. | 7.5 |