Description
SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
Remediation
References
Related Vulnerabilities
Joomla! Core 3.x.x Directory Traversal (3.0.0 - 3.9.24)
Apache HTTP Server Other Vulnerability (CVE-2001-0729)
WordPress Plugin WP People 'wp-people-popup.php' SQL Injection (2.0)
WordPress Plugin Simple Photo Gallery SQL Injection (1.7.9)
Python Inadequate Encryption Strength Vulnerability (CVE-2014-0224)