← All CVEs

CVE-2012-5357

critical · 9.8

Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data.

9.8
CVSS
67.8%
EPSS (exploit prob.)
99th
EPSS percentile
2017-10-30
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-19

Affected products

VendorProductAffected versions
ektronektron_content_management_system<= 8.02

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-5357