Description
dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters.
Remediation
References
Related Vulnerabilities
MediaWiki Improper Authentication Vulnerability (CVE-2014-2665)
SugarCRM Improper Restriction of XML External Entity Reference Vulnerability (CVE-2014-3244)
WordPress Plugin EZ SQL Reports Shortcode Widget and DB Backup Multiple Vulnerabilities (4.11.33)
WordPress Plugin WP Review Multiple Unspecified Vulnerabilities (2.0)