Security | Elar Lang
  • Blog
  • Full disclosure
  • Research
  • Workaround
  • Archives

CVE-2016-1000271 SQL injection in Joomla extension DT Register

SQL injection in Joomla extension DT Register allows remote unauthenticated attacker to execute malicous SQL commands. Step-by-Step Proof-of-Concept and interesting communication with vendor.

more ...

CVE-2016-8600 dotCMS - CAPTCHA bypass by reusing valid code

CVE-2016-8600 dotCMS before version 3.6.0 allows attacker to programmatically reuse valid captcha code.

more ...

CVE-2016-4803 dotCMS - email header injection vulnerability (Full Disclosure)

CVE-2016-4803 Email Header Injection vulnerability in dotCMS framework allows attacker to send malicious emails using "valid" and "trusted" email server.

more ...

Elar Lang - penterster, lecturer, researcher

Elar Lang

Pentester, lecturer, researcher
  • Recent Posts

    • CVE-2016-1000271 SQL injection in Joomla extension DT Register
    • CVE-2016-8600 dotCMS - CAPTCHA bypass by reusing valid code
    • CVE-2016-4803 dotCMS - email header injection vulnerability (Full Disclosure)
  • Categories

    • Blog
    • Full Disclosure
    • Research
    • Workaround

© 2016 Elar Lang · Powered by pelican-bootstrap3, Pelican, Bootstrap

Back to top