CVE-2016-2355
- EPSS 0.74%
- Veröffentlicht 19.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter to api/content/save/1.
CVE-2016-8908
- EPSS 2.04%
- Veröffentlicht 14.11.2016 23:20:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
CVE-2016-8907
- EPSS 1.99%
- Veröffentlicht 14.11.2016 23:20:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
CVE-2016-8906
- EPSS 2.04%
- Veröffentlicht 14.11.2016 23:20:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
CVE-2016-8905
- EPSS 1.99%
- Veröffentlicht 14.11.2016 23:20:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the sort parameter.
CVE-2016-8904
- EPSS 1.37%
- Veröffentlicht 14.11.2016 23:20:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
CVE-2016-8903
- EPSS 1.37%
- Veröffentlicht 14.11.2016 23:20:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
CVE-2016-8902
- EPSS 1.44%
- Veröffentlicht 14.11.2016 23:20:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQL commands via the sort parameter.
CVE-2016-8600
- EPSS 0.87%
- Veröffentlicht 28.10.2016 15:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.
CVE-2016-4803
- EPSS 0.4%
- Veröffentlicht 30.06.2016 17:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headers via CRLF sequences in the subject.