PoC Index

CVE-2012-5357

CRITICAL 9.8EPSS 67.8%

Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
67.78% chance of exploitation in the next 30 days, 99th percentile
Published
2017-10-30
Updated
2024-08-06

Proof-of-concept exploits (1)

Metasploit modules (1)

ExploitDB entries (1)

References

Related