Description
SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter to api/content/save/1.
Remediation
References
Related Vulnerabilities
WordPress Plugin Easy Google Maps Cross-Site Scripting (1.9.33)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-1000356)
Oracle Database Server CVE-2007-2109 Vulnerability (CVE-2007-2109)
WordPress Plugin Catch Themes Demo Import Arbitrary File Upload (1.7)
WordPress Plugin Connections Business Directory Unspecified Vulnerability (10.4.7)