CVE-2012-5357
critical · 9.8Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data.
9.8
CVSS
67.8%
EPSS (exploit prob.)
99th
EPSS percentile
2017-10-30
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-19
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ektron | ektron_content_management_system | <= 8.02 |
Check a specific version with /api/v1/cve/match.
References
- http://documentation.ektron.com/current/ReleaseNotes/Release8/8.02SP5.htm
- https://technet.microsoft.com/library/security/msvr12-016
- https://webstersprodigy.net/2012/10/25/cve-2012-5357cve-1012-5358-cool-ektron-xslt-rce-bugs/
- https://www.rapid7.com/db/modules/exploit/windows/http/ektron_xslt_exec
- http://documentation.ektron.com/current/ReleaseNotes/Release8/8.02SP5.htm
- https://technet.microsoft.com/library/security/msvr12-016
- https://webstersprodigy.net/2012/10/25/cve-2012-5357cve-1012-5358-cool-ektron-xslt-rce-bugs/
- https://www.rapid7.com/db/modules/exploit/windows/http/ektron_xslt_exec
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-5357