High severity8.8NVD Advisory· Published Nov 14, 2016· Updated Jun 17, 2026
CVE-2016-8905
CVE-2016-8905
Description
SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the sort parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/dotCMS/core/pull/8460/nvdPatchVendor Advisory
- github.com/dotCMS/core/pull/8468/nvdPatchVendor Advisory
- seclists.org/fulldisclosure/2016/Nov/0nvdExploitThird Party Advisory
- security.elarlang.eu/multiple-sql-injection-vulnerabilities-in-dotcms-8x-cve-full-disclosure.htmlnvdExploitThird Party Advisory
- www.securityfocus.com/bid/94311nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.