7.5
CVSSv2

CVE-2016-8902

Published: 14/11/2016 Updated: 29/11/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the categoriesServlet servlet in dotCMS prior to 3.3.1 allows remote not authenticated malicious users to execute arbitrary SQL commands via the sort parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dotcms dotcms

Exploits

dotCMS versions before 35, 331, and 332 suffer from multiple remote SQL injection vulnerabilities ...