Show filters
57 Total Results
Displaying 31-40 of 57
Sort by:
Attacker Value
Unknown

CVE-2016-10007

Disclosure Date: February 19, 2018 (last updated November 26, 2024)
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.
0
Attacker Value
Unknown

CVE-2016-10008

Disclosure Date: February 19, 2018 (last updated November 26, 2024)
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter.
0
Attacker Value
Unknown

CVE-2017-15219

Disclosure Date: October 10, 2017 (last updated November 26, 2024)
The dotCMS 4.1.1 application is vulnerable to Stored Cross-Site Scripting (XSS) affecting a vanity-urls Title field, a containers Description field, and a templates Description field.
0
Attacker Value
Unknown

CVE-2017-11466

Disclosure Date: July 20, 2017 (last updated November 26, 2024)
Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrators to upload .jsp files to arbitrary locations via directory traversal sequences in the fieldName parameter to servlets/ajax_file_upload. This results in arbitrary code execution by requesting the .jsp file at a /assets URI.
0
Attacker Value
Unknown

CVE-2017-6003

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields.
0
Attacker Value
Unknown

CVE-2017-5344

Disclosure Date: February 17, 2017 (last updated November 26, 2024)
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist were implemented in a new class, SQLUtil (main/java/com/dotmarketing/common/util/SQLUtil.java), as part of the remediation of CVE-2016-8902; however, these can be overcome in the case of the q and inode parameters to the /categoriesServlet path. Overcoming these controls permits a number of blind boolean SQL injection vectors in either parameter. The /categoriesServlet web path can be accessed remotely and without authentication in a default dotCMS deployment.
0
Attacker Value
Unknown

CVE-2017-5876

Disclosure Date: February 06, 2017 (last updated November 26, 2024)
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter.
0
Attacker Value
Unknown

CVE-2017-5877

Disclosure Date: February 06, 2017 (last updated November 26, 2024)
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter.
0
Attacker Value
Unknown

CVE-2017-5875

Disclosure Date: February 06, 2017 (last updated November 26, 2024)
XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.
0
Attacker Value
Unknown

CVE-2016-2355

Disclosure Date: December 19, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter to api/content/save/1.
0