CVE List

Id CVE No. Status Description Phase Votes Comments Actions
95725  CVE-2016-8905  Candidate  SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the sort parameter.  Assigned (20161024)  None (candidate not yet proposed)    View
95724  CVE-2016-8904  Candidate  SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.  Assigned (20161024)  None (candidate not yet proposed)    View
95723  CVE-2016-8903  Candidate  SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.  Assigned (20161024)  None (candidate not yet proposed)    View
95722  CVE-2016-8902  Candidate  SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQL commands via the sort parameter.  Assigned (20161024)  None (candidate not yet proposed)    View
95721  CVE-2016-8901  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161024)  None (candidate not yet proposed)    View

Page 1799 of 20943, showing 5 records out of 104715 total, starting on record 8991, ending on 8995

Actions