First published: Mon Oct 22 2012(Updated: )
SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name or (2) password field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Intelliants Subrion CMS | =2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-5212 is classified as a high severity vulnerability due to its potential for remote SQL injection attacks.
CVE-2011-5212 exploits the Subrion CMS by allowing attackers to inject arbitrary SQL commands through the user name or password fields.
To fix CVE-2011-5212, upgrade Subrion CMS to a version later than 2.0.4 that addresses this vulnerability.
CVE-2011-5212 specifically affects Subrion CMS version 2.0.4.
Yes, CVE-2011-5212 can lead to data exposure by allowing unauthorized access to sensitive information in the database.