Description
SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via the orderby parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Welcart e-Commerce PHP Object Injection (1.9.3)
WordPress Plugin U BuddyPress Forum Attachment 'fileurl' Parameter Remote File Disclosure (1.1.1)
OpenSSL Numeric Errors Vulnerability (CVE-2008-0891)
Oracle JRE CVE-2013-0440 Vulnerability (CVE-2013-0440)
WordPress Plugin Photo Gallery by Ays-Responsive Image Gallery SQL Injection (4.4.3)