CVE-2017-3187
- EPSS 0.27%
- Veröffentlicht 24.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:24:59
The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery. The dotCMS administrator panel contains a cross-site request forgery (CSRF) vulnerability. An attacker can perform actions with the same permis...
CVE-2016-10008
- EPSS 0.46%
- Veröffentlicht 19.02.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 02:43:05
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter.
CVE-2016-10007
- EPSS 0.46%
- Veröffentlicht 19.02.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 02:43:05
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.
CVE-2017-15219
- EPSS 0.19%
- Veröffentlicht 10.10.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The dotCMS 4.1.1 application is vulnerable to Stored Cross-Site Scripting (XSS) affecting a vanity-urls Title field, a containers Description field, and a templates Description field.
- EPSS 3.26%
- Veröffentlicht 20.07.2017 00:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrators to upload .jsp files to arbitrary locations via directory traversal sequences in the fieldName par...
CVE-2017-6003
- EPSS 0.23%
- Veröffentlicht 27.03.2017 02:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields.
CVE-2017-5344
- EPSS 8.15%
- Veröffentlicht 17.02.2017 07:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklis...
CVE-2017-5877
- EPSS 0.34%
- Veröffentlicht 06.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter.
CVE-2017-5876
- EPSS 0.34%
- Veröffentlicht 06.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter.
CVE-2017-5875
- EPSS 0.28%
- Veröffentlicht 06.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.