PT-2015-4979 · Ektron+1 · Ektron Content Management System+1

Matthias Kaiser

·

Published

2015-02-14

·

Updated

2015-02-17

·

CVE-2015-0931

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ektron Content Management System (CMS) versions 8.5 through 8.7 before 8.7sp2 Ektron Content Management System (CMS) version 9.0 before sp1
Description The issue allows remote attackers to execute arbitrary code via a crafted XSLT document, related to a "resource injection" issue, when the Saxon XSLT parser is used.
Recommendations For versions 8.5 through 8.7, update to 8.7sp2 or later to resolve the issue. For version 9.0, update to sp1 or later to resolve the issue.

Fix

RCE

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-0931

Affected Products

Ektron Content Management System
Saxon Xslt Parser