Page 7 of 32 results (0.003 seconds)

CVSS: 4.3EPSS: 0%CPEs: 9EXPL: 1

Multiple cross-site scripting (XSS) vulnerabilities in dotCMS before 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) _loginUserName parameter to application/login/login.html, (2) my_account_login parameter to c/portal_public/login, or (3) email parameter to forgotPassword. Múltiples vulnerabilidades de XSS en dotCMS anterior a 2.3.2 permiten a atacantes remotos inyectar script Web o HTML arbitrarios a través del (1) parámetro _loginUserName hacia application/login/login.html, (2) parámetro my_account_login hacia c/portal_public/login o (3) parámetro email hacia forgotPassword. • http://dotcms.com/security/SI-14 http://secunia.com/advisories/53265 https://github.com/dotCMS/dotCMS/issues/2949 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.0EPSS: 0%CPEs: 2EXPL: 0

dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template. dotCMS v1.9 anteriores a v1.9.5.1 permite a usuarios remotos autenticados ejecutar código JAVA a través de las plantillas (1) XSLT o (2) Velocity manipuladas. • http://dotcms.com/dotCMSVersions http://osvdb.org/82240 http://secunia.com/advisories/49276 http://www.kb.cert.org/vuls/id/898083 http://www.securityfocus.com/bid/53688 https://gist.github.com/2627440 https://github.com/dotCMS/dotCMS/issues/261 https://github.com/dotCMS/dotCMS/issues/281 • CWE-264: Permissions, Privileges, and Access Controls •