CVE-2011-5212: SQL Injection
Published Oct 22, 2012
·Updated
SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name or (2) password field.
Affected Software
1 affected component
Intelliants Subrion CMS=2.0.4
Event History
Oct 22, 2012
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-5212?
CVE-2011-5212 is classified as a high severity vulnerability due to its potential for remote SQL injection attacks.
2
How does CVE-2011-5212 exploit the Subrion CMS?
CVE-2011-5212 exploits the Subrion CMS by allowing attackers to inject arbitrary SQL commands through the user name or password fields.
3
How do I fix CVE-2011-5212?
To fix CVE-2011-5212, upgrade Subrion CMS to a version later than 2.0.4 that addresses this vulnerability.
4
What versions of Subrion CMS are affected by CVE-2011-5212?
CVE-2011-5212 specifically affects Subrion CMS version 2.0.4.
5
Can CVE-2011-5212 lead to data exposure?
Yes, CVE-2011-5212 can lead to data exposure by allowing unauthorized access to sensitive information in the database.