Description
SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/plaincall/UserAjax.getUsersList.dwr.
Remediation
References
Related Vulnerabilities
WordPress Plugin Seo Optimized Images Malicious Code (2.1.2)
RubyGems Improper Input Validation Vulnerability (CVE-2018-1000077)
Undertow Uncontrolled Resource Consumption Vulnerability (CVE-2021-3629)
Oracle JRE CVE-2012-0503 Vulnerability (CVE-2012-0503)
WordPress Plugin Special Text Boxes Unspecified Vulnerability (5.5.102)