Sploitus

CVE-2016-3688

1 known exploit for CVE-2016-3688

SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/plaincall/UserAjax.getUsersList.dwr.

Affected products
Dotcms
Dotcms
≤ 3.3.1
Fix
Available
CVSS 3.0
6.5 MEDIUM
EPSS
1.6% (73th percentile)
Weakness
CWE-200
NVD status
Modified
Published
2016-04-19
CVE-2016-3688 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2016-3688

Proof-of-concept code and exploit modules indexed by Sploitus