Subrion CMS是Subrion团队开发的一套基于PHP的内容管理系统(CMS)。该系统可被集成到网站,并支持多种扩展插件等。 Subrion CMS 4.1.5.10之前的版本中的/front/search.php文件存在SQL注入漏洞。远程攻击者可借助$_GET数组利用该漏洞执行任意的SQL命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-11444.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2017-11440 | Sitecore 路径遍历漏洞 | |
| CVE-2017-9245 | Google News and Weather application for Android 安全漏洞 | |
| CVE-2017-11456 | Geneko GWR路由器路径遍历漏洞 | |
| CVE-2017-11450 | ImageMagick 安全漏洞 | |
| CVE-2017-11449 | ImageMagick 安全漏洞 | |
| CVE-2017-11448 | ImageMagick 信息泄露漏洞 | |
| CVE-2017-11447 | ImageMagick 资源管理错误漏洞 | |
| CVE-2017-11446 | ImageMagick 安全漏洞 | |
| CVE-2017-11445 | Subrion CMS SQL注入漏洞 | |
| CVE-2017-11441 | cPanel 跨站脚本漏洞 | |
| CVE-2017-11464 | GNOME librsvg 安全漏洞 | |
| CVE-2017-11439 | Sitecore 跨站脚本漏洞 | |
| CVE-2017-11436 | D-Link DIR-615 安全漏洞 | |
| CVE-2017-11435 | Humax Wi-Fi Router HG100R 信息泄露漏洞 | |
| CVE-2017-10801 | phpSocial 跨站脚本漏洞 | |
| CVE-2017-9764 | MetInfo 跨站脚本漏洞 | |
| CVE-2016-7509 | GLPI 跨站脚本漏洞 | |
| CVE-2016-7507 | GLPI 跨站请求伪造漏洞 | |
| CVE-2017-7977 | Unicon Software eLux RP Screensavercc组件安全漏洞 | |
| CVE-2017-11465 | Ruby UTF-8解析器安全漏洞 |
No comments yet