6.5
CVSSv2

CVE-2016-10008

Published: 19/02/2018 Updated: 05/03/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS prior to 3.7.2 and 4.x prior to 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

dotcms dotcms

Exploits

dotCMS versions prior to 411 suffer from remote SQL injection vulnerabilities ...