Vulnerabilities > Ektron > Ektron Content Management System > 8.5.0

DATE CVE VULNERABILITY TITLE RISK
2015-02-14 CVE-2015-0931 Injection vulnerability in Ektron Content Management System 8.5.0/8.7.0/8.9.0
Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attackers to execute arbitrary code via a crafted XSLT document, related to a "resource injection" issue.
network
ektron CWE-74
6.8
2015-02-14 CVE-2015-0923 Unspecified vulnerability in Ektron Content Management System 8.5.0/8.7.0/8.9.0
The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference within an XML document named in the xslt parameter, related to an XML External Entity (XXE) issue.
network
low complexity
ektron
5.0