← Back to CVE List

CVE-2012-5357

Published: 2017-10-30T14:29Z
Last Modified: 2024-11-21T01:44Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt