Description
SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2011-0877 Vulnerability (CVE-2011-0877)
WordPress Plugin Easy2Map Photos Multiple Vulnerabilities (1.0.9)
OpenSSL Cryptographic Issues Vulnerability (CVE-2012-2686)
WordPress Plugin InstaWP Connect-1-click WP Staging & Migration Arbitrary File Upload (0.1.0.38)
Python Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-1015)