CVE-2013-3484
https://notcve.org/view.php?id=CVE-2013-3484
Multiple cross-site scripting (XSS) vulnerabilities in dotCMS before 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) _loginUserName parameter to application/login/login.html, (2) my_account_login parameter to c/portal_public/login, or (3) email parameter to forgotPassword. Múltiples vulnerabilidades de XSS en dotCMS anterior a 2.3.2 permiten a atacantes remotos inyectar script Web o HTML arbitrarios a través del (1) parámetro _loginUserName hacia application/login/login.html, (2) parámetro my_account_login hacia c/portal_public/login o (3) parámetro email hacia forgotPassword. • http://dotcms.com/security/SI-14 http://secunia.com/advisories/53265 https://github.com/dotCMS/dotCMS/issues/2949 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2008-3708 – dotCMS 1.6 - 'id' Local File Inclusion
https://notcve.org/view.php?id=CVE-2008-3708
Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter to (1) news/index.dot and (2) getting_started/macros/macros_detail.dot. Múltiples vulnerabilidades de salto de directorio en dotCMS 1.6.0.9 permiten a atacantes remotos leer ficheros arbitrariamente mediante un .. (punto punto) en los parámetros id de (1) news/index.dot y (2) getting_started/macros/macros_detail.dot. • https://www.exploit-db.com/exploits/6247 http://secunia.com/advisories/31516 http://securityreason.com/securityalert/4163 http://www.securityfocus.com/bid/30703 https://exchange.xforce.ibmcloud.com/vulnerabilities/44491 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •