CVE-2016-8907

8.8HIGH

SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.

게시됨: 11/14/2016업데이트됨: 4/12/2025

설명

SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.

AI 분석AI 기반

영향받는 제품

dotcmsdotcms

참조