VendorsEktronektron_content_management_system8.7.0
Vulnerabilities

Ektron Content Management System (CMS) 8.7.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2015-0931
Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attackers to execute arbitrary code via a crafted XSLT document, related to a "resource injection" issue.
Published 2015-02-14 · Modified
6.8EPSS 0.024
CVE-2015-0923
The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference within an XML document named in the xslt parameter, related to an XML External Entity (XXE) issue.
Published 2015-02-14 · Modified
5.0EPSS 0.220
CVE-2014-2729
Cross-site scripting (XSS) vulnerability in content.aspx in Ektron CMS 8.7 before 8.7.0.055 allows remote authenticated users to inject arbitrary web script or HTML via the category0 parameter, which is not properly handled when displaying the Subjects tab in the View Properties menu option.
Published 2014-04-25 · Modified
3.5EPSS 0.010