IntelliantsCVEs & Vulnerabilities

65 CVEs affecting Intelliants products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

subrion cms 45subrion 25elitius 2esyndicat 2
CVE-2017-6068HIGH

Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.

27 Mar 2017
8.8
CVSS
CVE-2017-6066HIGH

Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.

27 Mar 2017
8.8
CVSS
CVE-2017-6013CRITICAL

Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.

27 Mar 2017
9.8
CVSS
CVE-2017-6002HIGH

Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.

27 Mar 2017
8.8
CVSS
CVE-2017-5543CRITICAL

includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.

20 Jan 2017
9.8
CVSS
CVE-2015-4129MEDIUM

SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via modified serialized data in a salt cookie.

5 Jul 2015
6.5
CVSS
CVE-2014-9120MEDIUM

Cross-site scripting (XSS) vulnerability in Subrion CMS before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to subrion/search/.

10 Dec 2014
4.3
CVSS
CVE-2012-5452MEDIUMpoc

Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) multi_title parameter to blocks/add/; (2) cost, (3) days, or (4) title[en] parameter to plans/add/; (5) name or (6) title[en] parameter to fields/group/add/ in admin/manage/; or (7) f[accounts][fullname] or (8) f[accounts][username] parameter to advsearch/. NOTE: This might overlap CVE-2011-5211. NOTE: it was later reported that the f[accounts][fullname] and f[accounts][username] vectors might also affect 2.2.2.

23 Oct 2012
4.3
CVSS
CVE-2012-4773MEDIUMpoc

Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of administrators for requests that add, delete, or modify sensitive information, as demonstrated by adding an administrator account via an add action to admin/accounts/add/.

23 Oct 2012
6.8
CVSS
CVE-2012-4772HIGHpoc

SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via the plan_id parameter.

23 Oct 2012
7.5
CVSS
CVE-2012-4771MEDIUMpoc

Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/accounts/, (2) admin/manage/, or (3) admin/manage/blocks/edit/; or (4) group parameter to admin/configuration/. NOTE: The f[accounts][fullname] and f[accounts][username] vectors are covered in CVE-2012-5452.

23 Oct 2012
4.3
CVSS
CVE-2011-5212HIGHpoc

SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name or (2) password field.

23 Oct 2012
7.5
CVSS
CVE-2011-5211MEDIUMpoc

Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the title field. NOTE: some of these details are obtained from third party information. NOTE: this might overlap CVE-2012-5452.

23 Oct 2012
4.3
CVSS
CVE-2010-4504MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in eSyndiCat Directory 2.3 allow remote attackers to inject arbitrary web script or HTML via the title parameter to (1) suggest-category.php and (2) suggest-listing.php.

8 Dec 2010
4.3
CVSS
CVE-2008-6924MEDIUMpoc

Multiple cross-site scripting (XSS) vulnerabilities in register.php in eSyndiCat Directory 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) email, (3) password, (4) password2, (5) security_code, and (6) register parameters.

10 Aug 2009
4.3
CVSS
CVE-2009-1659MEDIUMpoc

Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files via an avatar file with an accepted Content-Type such as image/gif, then requesting the file in admin/banners/.

18 May 2009
6.8
CVSS
CVE-2009-1506MEDIUMpoc

SQL injection vulnerability in classes/Xp.php in eLitius 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to banner-details.php.

1 May 2009
6.8
CVSS
← PrevPage 2 / 2Next →
Intelliants CVEs & Vulnerabilities — 65 Tracked — Page 2