dotCMS Blind Boolean SQL Injection... CVE-2017-5344 CNNVD-201701-301

7.5 AV AC AU C I A
发布: 2017-02-17
修订: 2017-09-01

## Product Description dotCMS is a scalable, java based, open source content management system (CMS) that has been designed to manage and deliver personalized, permission based content experiences across multiple channels. dotCMS can serve as the plaform for sites, mobile apps, mini-sites, portals, intranets or as a headless CMS (content is consumed via RESTful APIs). dotCMS is used everywhere, from running small sites to powering multi-node installations for governemnts, Fortune 100 companies, Universities and Global Brands. A dotCMS environment can scale to support hundreds of editors managing thousands of sites with millions of content objects. ## Vulnerability Type Blind Boolean SQL injection ## Vulnerability Description dotCMS versions up to 3.6.1 (and possibly others) are vulnerable to blind boolean SQL injection in the q and inode parameters at the /categoriesServlet path. This servlet is a remotely accessible, unauthenticated function of default dotCMS installations and can...

0%
当前有3条漏洞利用/PoC
当前有1条受影响产品信息