Vulnerabilities (CVE)

Filtered by vendor Dotcms Subscribe
Filtered by product Dotcms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-3708 1 Dotcms 1 Dotcms 2017-09-29 4.3 MEDIUM N/A
Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter to (1) news/index.dot and (2) getting_started/macros/macros_detail.dot.
CVE-2008-2397 1 Dotcms 1 Dotcms 2017-08-08 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in search-results.dot in dotCMS 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2013-3484 1 Dotcms 1 Dotcms 2014-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in dotCMS before 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) _loginUserName parameter to application/login/login.html, (2) my_account_login parameter to c/portal_public/login, or (3) email parameter to forgotPassword.
CVE-2012-1826 1 Dotcms 1 Dotcms 2012-11-27 6.0 MEDIUM N/A
dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template.