CVE-2008-3708 – dotCMS 1.6 - 'id' Local File Inclusion
https://notcve.org/view.php?id=CVE-2008-3708
Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter to (1) news/index.dot and (2) getting_started/macros/macros_detail.dot. Múltiples vulnerabilidades de salto de directorio en dotCMS 1.6.0.9 permiten a atacantes remotos leer ficheros arbitrariamente mediante un .. (punto punto) en los parámetros id de (1) news/index.dot y (2) getting_started/macros/macros_detail.dot. • https://www.exploit-db.com/exploits/6247 http://secunia.com/advisories/31516 http://securityreason.com/securityalert/4163 http://www.securityfocus.com/bid/30703 https://exchange.xforce.ibmcloud.com/vulnerabilities/44491 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2008-2397
https://notcve.org/view.php?id=CVE-2008-2397
Cross-site scripting (XSS) vulnerability in search-results.dot in dotCMS 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Vulnerabilidad de secuencias de comandos en sitios cruzados en search-results.dot de dotCMS, permite a atacantes remotos, inyectar secuencias de comandos web o HTML a través del parámetro search_query. NOTA: el origen de esta información es desconocido; los detalles se han obtenido únicamente de información de terceros. • http://secunia.com/advisories/30307 http://www.securityfocus.com/bid/29287 https://exchange.xforce.ibmcloud.com/vulnerabilities/42525 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •