Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data.
References
Link | Resource |
---|---|
http://documentation.ektron.com/current/ReleaseNotes/Release8/8.02SP5.htm | Issue Tracking Vendor Advisory |
https://technet.microsoft.com/library/security/msvr12-016 | Issue Tracking Release Notes Third Party Advisory |
https://webstersprodigy.net/2012/10/25/cve-2012-5357cve-1012-5358-cool-ektron-xslt-rce-bugs/ | Exploit Issue Tracking Third Party Advisory |
https://www.rapid7.com/db/modules/exploit/windows/http/ektron_xslt_exec | Exploit Issue Tracking Third Party Advisory |
http://documentation.ektron.com/current/ReleaseNotes/Release8/8.02SP5.htm | Issue Tracking Vendor Advisory |
https://technet.microsoft.com/library/security/msvr12-016 | Issue Tracking Release Notes Third Party Advisory |
https://webstersprodigy.net/2012/10/25/cve-2012-5357cve-1012-5358-cool-ektron-xslt-rce-bugs/ | Exploit Issue Tracking Third Party Advisory |
https://www.rapid7.com/db/modules/exploit/windows/http/ektron_xslt_exec | Exploit Issue Tracking Third Party Advisory |
Configurations
History
21 Nov 2024, 01:44
Type | Values Removed | Values Added |
---|---|---|
References | () http://documentation.ektron.com/current/ReleaseNotes/Release8/8.02SP5.htm - Issue Tracking, Vendor Advisory | |
References | () https://technet.microsoft.com/library/security/msvr12-016 - Issue Tracking, Release Notes, Third Party Advisory | |
References | () https://webstersprodigy.net/2012/10/25/cve-2012-5357cve-1012-5358-cool-ektron-xslt-rce-bugs/ - Exploit, Issue Tracking, Third Party Advisory | |
References | () https://www.rapid7.com/db/modules/exploit/windows/http/ektron_xslt_exec - Exploit, Issue Tracking, Third Party Advisory |
Information
Published : 2017-10-30 14:29
Updated : 2024-11-21 01:44
NVD link : CVE-2012-5357
Mitre link : CVE-2012-5357
CVE.ORG link : CVE-2012-5357
JSON object : View
Products Affected
ektron
- ektron_content_management_system
CWE
CWE-19
Data Processing Errors