CVE-2016-8902
SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQL commands via the sort parameter.
- Affected products
- Dotcms
- Dotcms
- ≤ 3.3
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 2.8% (85th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2016-11-14
CVE-2016-8902 at NVD
2 known exploits for CVE-2016-8902
Proof-of-concept code and exploit modules indexed by Sploitus