Critical severity9.8NVD Advisory· Published Nov 14, 2016· Updated Jun 17, 2026
CVE-2016-8902
CVE-2016-8902
Description
SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQL commands via the sort parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/dotCMS/core/pull/8460/nvdPatchVendor Advisory
- github.com/dotCMS/core/pull/8468/nvdPatchVendor Advisory
- security.elarlang.eu/multiple-sql-injection-vulnerabilities-in-dotcms-8x-cve-full-disclosure.htmlnvdExploitThird Party Advisory
- seclists.org/fulldisclosure/2016/Nov/0nvdThird Party Advisory
- www.securityfocus.com/bid/94311nvdTechnical DescriptionVDB Entry
News mentions
0No linked articles in our index yet.