Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data.
References
Link | Resource |
---|---|
https://www.rapid7.com/db/modules/exploit/windows/http/ektron_xslt_exec | Exploit Issue Tracking Third Party Advisory |
https://webstersprodigy.net/2012/10/25/cve-2012-5357cve-1012-5358-cool-ektron-xslt-rce-bugs/ | Exploit Issue Tracking Third Party Advisory |
https://technet.microsoft.com/library/security/msvr12-016 | Issue Tracking Release Notes Third Party Advisory |
http://documentation.ektron.com/current/ReleaseNotes/Release8/8.02SP5.htm | Issue Tracking Vendor Advisory |
Configurations
Information
Published : 2017-10-30 07:29
Updated : 2017-11-18 09:39
NVD link : CVE-2012-5357
Mitre link : CVE-2012-5357
JSON object : View
CWE
CWE-19
Data Processing Errors
Products Affected
ektron
- ektron_content_management_system