Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 29 min 102 bronnen 1 kritiek 35 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2015-0931

MEDIUM · 6.8 CVSS Gepubliceerd: CWE-74

Beschrijving

Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attackers to execute arbitrary code via a crafted XSLT document, related to a "resource injection" issue.

Vendors

Ektron

Affected products

Ektron Content Management System

References