9.8

CVE-2012-5357

Exploit
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EktronEktron Content Management System Updatesp4 Version <= 8.02
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 67.78% 0.992
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://documentation.ektron.com/current/ReleaseNotes/Release8/8.02SP5.htm
Vendor Advisory
Issue Tracking
https://technet.microsoft.com/library/security/msvr12-016
Third Party Advisory
Release Notes
Issue Tracking
https://webstersprodigy.net/2012/10/25/cve-2012-5357cve-1012-5358-cool-ektron-xslt-rce-bugs/
Third Party Advisory
Exploit
Issue Tracking
https://www.rapid7.com/db/modules/exploit/windows/http/ektron_xslt_exec
Third Party Advisory
Exploit
Issue Tracking