Show filters
57 Total Results
Displaying 41-50 of 57
Sort by:
Attacker Value
Unknown
CVE-2016-8903
Disclosure Date: November 14, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
0
Attacker Value
Unknown
CVE-2016-8902
Disclosure Date: November 14, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQL commands via the sort parameter.
0
Attacker Value
Unknown
CVE-2016-8908
Disclosure Date: November 14, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
0
Attacker Value
Unknown
CVE-2016-8906
Disclosure Date: November 14, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
0
Attacker Value
Unknown
CVE-2016-8907
Disclosure Date: November 14, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
0
Attacker Value
Unknown
CVE-2016-8905
Disclosure Date: November 14, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the sort parameter.
0
Attacker Value
Unknown
CVE-2016-8904
Disclosure Date: November 14, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
0
Attacker Value
Unknown
CVE-2016-8600
Disclosure Date: October 28, 2016 (last updated November 25, 2024)
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.
0
Attacker Value
Unknown
CVE-2016-4803
Disclosure Date: June 30, 2016 (last updated November 25, 2024)
CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headers via CRLF sequences in the subject.
0
Attacker Value
Unknown
CVE-2016-4040
Disclosure Date: April 19, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via the orderby parameter.
0