Vulnerabilities > Ektron > Ektron Content Management System > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-07-25 | CVE-2016-6133 | Cross-site Scripting vulnerability in Ektron Content Management System 8.7.0/9.1 Cross-site scripting (XSS) vulnerability in Ektron Content Management System before 9.1.0.184SP3(9.1.0.184.3.127) allows remote attackers to inject arbitrary web script or HTML via the rptStatus parameter in a Report action to WorkArea/SelectUserGroup.aspx. | 4.3 |
2017-07-03 | CVE-2016-6201 | Cross-site Scripting vulnerability in Ektron Content Management System 8.7.0/9.1 Cross-site scripting (XSS) vulnerability in Ektron Content Management System (CMS) before 9.1.0.184 SP3 (9.1.0.184.3.127) allows remote attackers to inject arbitrary web script or HTML via the ContType parameter in a ViewContentByCategory action to WorkArea/content.aspx. | 4.3 |
2015-06-09 | CVE-2015-3624 | Cross-Site Request Forgery (CSRF) vulnerability in Ektron Content Management System 8.7.0/9.1 Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.120) allows remote attackers to hijack the authentication of content administrators for requests that delete content via a delete action. | 5.8 |
2015-02-14 | CVE-2015-0931 | Injection vulnerability in Ektron Content Management System 8.5.0/8.7.0/8.9.0 Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attackers to execute arbitrary code via a crafted XSLT document, related to a "resource injection" issue. | 6.8 |
2015-02-14 | CVE-2015-0923 | Unspecified vulnerability in Ektron Content Management System 8.5.0/8.7.0/8.9.0 The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference within an XML document named in the xslt parameter, related to an XML External Entity (XXE) issue. | 5.0 |