CVE-2012-1826
08.06.2012, 16:55
dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template.Enginsight
Vendor | Product | Version |
---|---|---|
dotcms | dotcms | 1.9 |
dotcms | dotcms | 1.9.2.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References