Show filters
57 Total Results
Displaying 41-50 of 57
Sort by:
Attacker Value
Unknown

CVE-2016-8903

Disclosure Date: November 14, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
0
Attacker Value
Unknown

CVE-2016-8902

Disclosure Date: November 14, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQL commands via the sort parameter.
0
Attacker Value
Unknown

CVE-2016-8908

Disclosure Date: November 14, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
0
Attacker Value
Unknown

CVE-2016-8906

Disclosure Date: November 14, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
0
Attacker Value
Unknown

CVE-2016-8907

Disclosure Date: November 14, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
0
Attacker Value
Unknown

CVE-2016-8905

Disclosure Date: November 14, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the sort parameter.
0
Attacker Value
Unknown

CVE-2016-8904

Disclosure Date: November 14, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
0
Attacker Value
Unknown

CVE-2016-8600

Disclosure Date: October 28, 2016 (last updated November 25, 2024)
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.
0
Attacker Value
Unknown

CVE-2016-4803

Disclosure Date: June 30, 2016 (last updated November 25, 2024)
CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headers via CRLF sequences in the subject.
0
Attacker Value
Unknown

CVE-2016-4040

Disclosure Date: April 19, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via the orderby parameter.
0