Description
SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter to api/content/save/1.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Easy Gallery 'select_gallery' Parameter Cross-Site Scripting (1.7)
Ampache Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2008-3929)
osTicket Other Vulnerability (CVE-2005-1439)
WordPress 4.8.x Arbitrary File Deletion Vulnerability (4.8 - 4.8.6)