Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

3Psil0Nlambda

#21112of 53,608
11.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2012-2188
4.3
2012-10-22
Subrion · Subrion Cms · CVE-2011-5211
**Name of the Vulnerable Software and Affected Versions** Subrion CMS version 2.0.4 **Description** A cross-site scripting (XSS) issue exists in the poll module, allowing remote attackers to inject arbitrary web script or HTML via the `title` field. **Recommendations** For Subrion CMS version 2.0.4, consider restricting access to the poll module until a fix is available, and avoid using the `title` field in the poll module to minimize the risk of exploitation.
PT-2012-2189
7.5
2012-10-22
Subrion · Subrion Cms · CVE-2011-5212
**Name of the Vulnerable Software and Affected Versions** Subrion CMS version 2.0.4 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the `user name` or `password` field in the admin/index.php file. **Recommendations** For Subrion CMS version 2.0.4, consider updating to a newer version that contains a fix for this issue. As a temporary workaround, restrict access to the admin/index.php file to minimize the risk of exploitation. Avoid using the `user name` and `password` fields in the affected file until the issue is resolved.