[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":38,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":45,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":51,"vulnerability-17210":58},[4,15,23,28],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",false,[11],"/vulnerabilities-exploits/","See CVE details","secondary","wp2shell",{"title":16,"slug":17,"text":18,"link":19,"external":9,"targets":20,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https://pentest-tools.com/pricing",[21],"/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":24,"slug":25,"text":18,"link":19,"external":9,"targets":26,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - detection)","wp2shell-cve-page",[27],"/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",{"title":29,"slug":30,"text":31,"link":32,"external":33,"targets":34,"cta":36,"variant":37,"campaign_id":30},"Office Hours #8 - AI Survey","office-hours-8","Free live Office Hours, Wed Jul 29: The triage tax - why AI finds more and proves less","https://zoom.us/webinar/register/5117815316917/WN_kMwWqNEwQJa8NvfsFw89vw",true,[35],"/","Save your spot","primary",["Island",39],{"key":40,"params":41,"result":43},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":42},"{}",{"head":44},{},["Island",46],{"key":47,"params":48,"result":49},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":42},{"head":50},{},["Island",52],{"key":53,"params":54,"result":56},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":55},"{\"text-color\":\"gray\"}",{"head":57},{},{"id":59,"detectable_with":60,"vuln_details":67,"vuln_id":86,"name":87,"published":88,"updated":68},17210,{"tool":61,"engine":64},{"id":62,"name":63},1,"Network Scanner",{"id":65,"name":66},3,"OpenVAS",{"id":59,"codename":68,"description":68,"severity":69,"risk_description":70,"public_description":71,"public_recommendation":72,"recommendation":68,"references":73,"cvssv3":75,"epss_score":76,"epss_percentile":77,"cve":78,"in_cisa_catalog":9,"date":68,"software_type":68,"vendor":68,"product":68,"ptt_exploit_capabilities":68},null,"high","The following vulnerabilities exist: - CVE-2016-8902: SQL injection (SQLi) in the categoriesServlet allows remote not authenticated attackers to execute arbitrary SQL commands via the sort parameter. - CVE-2016-8903: SQL injection (SQLi) in the Site Browser > Templates pages screen allows remote authenticated attackers to execute arbitrary SQL commands via the _EXT_13_orderby parameter. - CVE-2016-8904: SQL injection (SQLi) in the Site Browser > Containers pages screen allows remote authenticated attackers to execute arbitrary SQL commands via the _EXT_12_orderby parameter. - CVE-2016-8905: SQL injection (SQLi) in the JSONTags servlet allows remote authenticated attackers to execute arbitrary SQL commands via the sort parameter. - CVE-2016-8906: SQL injection (SQLi) in the Site Browser > Links page screen allows remote authenticated attackers to execute arbitrary SQL commands via the _EXT_18_orderby parameter. - CVE-2016-8907: SQL injection (SQLi) in the Content Types > Content Types screen allows remote authenticated attackers to execute arbitrary SQL commands via the _EXT_STRUCTURE_orderBy and _EXT_STRUCTURE_direction parameters. - CVE-2016-8908: SQL injection (SQLi) in the Site Browser > HTML pages screen allows remote authenticated attackers to execute arbitrary SQL commands via the _EXT_15_orderby parameter. An attacker may execute arbitrary SQL commands.","dotCMS is prone to multiple SQL injection (SQLi) vulnerabilities.","Update to version 3.3.1 or later.",[74],"https://security.elarlang.eu/multiple-sql-injection-vulnerabilities-in-dotcms-8x-cve-full-disclosure.html",8.8,0.0275,0.84665,[79,80,81,82,83,84,85],"CVE-2016-8902","CVE-2016-8903","CVE-2016-8904","CVE-2016-8905","CVE-2016-8906","CVE-2016-8907","CVE-2016-8908","NETSCAN-OPENVAS-1.3.6.1.4.1.25623.1.0.106364","dotCMS \u003C 3.3.1 Multiple SQLi Vulnerabilities - Active Check","2018-01-02T00:00:00Z"]