CVE-2012-4771
subrion CMS 2.2.1 - Multiple Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/accounts/, (2) admin/manage/, or (3) admin/manage/blocks/edit/; or (4) group parameter to admin/configuration/. NOTE: The f[accounts][fullname] and f[accounts][username] vectors are covered in CVE-2012-5452.
Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en Subrion CMS antes de v2.2.3, permite a atacantes remotos ejecutar secuencias de comandos web o HTML a través del parámetro id a (1) admin/accounts/, (2) admin/manage/, o (3) admin/manage/blocks/edit/; o (4) el parámetro group a admin/configuration/. NOTA Los vectores f[accounts][fullname] y f[accounts][username] están recogidos en CVE-2012-5452.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-09-06 CVE Reserved
- 2012-10-22 CVE Published
- 2012-10-22 First Exploit
- 2024-08-06 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.org/files/117460/Subrion-CMS-2.2.1-XSS-CSRF-SQL-Injection.html | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/79468 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/22159 | 2012-10-22 | |
http://archives.neohapsis.com/archives/bugtraq/2012-10/0096.html | 2024-08-06 | |
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2012-5105.php | 2024-08-06 | |
https://www.htbridge.com/advisory/HTB23113 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/51013 | 2017-08-29 | |
http://www.subrion.com/forums/announcements/934-subrion-2-2-3-open-source-cms-core-available.html | 2017-08-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Intelliants Search vendor "Intelliants" | Subrion Cms Search vendor "Intelliants" for product "Subrion Cms" | <= 2.2.2 Search vendor "Intelliants" for product "Subrion Cms" and version " <= 2.2.2" | - |
Affected
| ||||||
Intelliants Search vendor "Intelliants" | Subrion Cms Search vendor "Intelliants" for product "Subrion Cms" | 2.0.4 Search vendor "Intelliants" for product "Subrion Cms" and version "2.0.4" | - |
Affected
| ||||||
Intelliants Search vendor "Intelliants" | Subrion Cms Search vendor "Intelliants" for product "Subrion Cms" | 2.2.0 Search vendor "Intelliants" for product "Subrion Cms" and version "2.2.0" | - |
Affected
| ||||||
Intelliants Search vendor "Intelliants" | Subrion Cms Search vendor "Intelliants" for product "Subrion Cms" | 2.2.1 Search vendor "Intelliants" for product "Subrion Cms" and version "2.2.1" | - |
Affected
|