Description
SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
Remediation
References
Related Vulnerabilities
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-8563)
WordPress Plugin WP Support Plus Responsive Ticket System Privilege Escalation (7.1.4)
WordPress Plugin Edit Author Slug Cross-Site Scripting (1.0.5.1)
WordPress 4.0.x Arbitrary File Deletion Vulnerability (4.0 - 4.0.23)
WordPress Plugin GiveWP-Donation and Fundraising Platform Cross-Site Scripting (2.4.6)