Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2015-0923 | First vendor Publication | 2015-02-13 |
Vendor | Cve | Last vendor Modification | 2015-02-17 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference within an XML document named in the xslt parameter, related to an XML External Entity (XXE) issue. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0923 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 4 |
Snort® IPS/IDS
Date | Description |
---|---|
2016-11-22 | Ektron ServerControlWS.asmx XSL transform code injection attempt RuleID : 40493 - Revision : 3 - Type : SERVER-WEBAPP |
Sources (Detail)
Source | Url |
---|---|
CERT-VN | http://www.kb.cert.org/vuls/id/377644 |
Alert History
Date | Informations |
---|---|
2021-05-04 12:36:31 |
|
2021-04-22 01:44:15 |
|
2020-05-23 13:17:06 |
|
2020-05-23 00:43:45 |
|
2015-02-17 21:25:07 |
|
2015-02-14 09:23:29 |
|