CVE-2016-3688
SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/plaincall/UserAjax.getUsersList.dwr.
- Affected products
- Dotcms
- Dotcms
- ≤ 3.3.1
- Fix
- Available
- CVSS 3.0
- 6.5 MEDIUM
- EPSS
- 1.6% (73th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2016-04-19
CVE-2016-3688 at NVD
1 known exploit for CVE-2016-3688
Proof-of-concept code and exploit modules indexed by Sploitus