CVE-2016-8902
9.8CRITICALSQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQL commands via the sort parameter.
게시됨: 11/14/2016업데이트됨: 4/12/2025
설명
SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQL commands via the sort parameter.
AI 분석AI 기반
영향받는 제품
dotcmsdotcms
참조
- http://seclists.org/fulldisclosure/2016/Nov/0Third Party Advisory
- http://www.securityfocus.com/bid/94311Technical DescriptionVDB Entry
- https://github.com/dotCMS/core/pull/8460/PatchVendor Advisory
- https://github.com/dotCMS/core/pull/8468/PatchVendor Advisory
- https://security.elarlang.eu/multiple-sql-injection-vulnerabilities-in-dotcms-8x-cve-full-disclosure.htmlExploitThird Party Advisory
- http://seclists.org/fulldisclosure/2016/Nov/0Third Party Advisory
- http://www.securityfocus.com/bid/94311Technical DescriptionVDB Entry
- https://github.com/dotCMS/core/pull/8460/PatchVendor Advisory
- https://github.com/dotCMS/core/pull/8468/PatchVendor Advisory
- https://security.elarlang.eu/multiple-sql-injection-vulnerabilities-in-dotcms-8x-cve-full-disclosure.htmlExploitThird Party Advisory