ektron kayıtları
ektron üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %16,7
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-19 Data Processing Errors2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
59Planlayın | CVE-2012-5357Silahlaştırılmış | Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remotektron · ektron content management system · CWE-19 | Kritik9,8 | — | %67,8 | 30 Eki 2017 |
40Planlayın | CVE-2012-5358İstismar yok | The XSLTCompiledTransform function in Ektron Content Management System (CMS) before 8.02 SP5 configures the XSL with enableDocumentFunction ektron · ektron content management system · CWE-19 | Kritik9,8 | — | %1,9 | 30 Eki 2017 |
40Planlayın | CVE-2008-3499İstismar yok | Unspecified vulnerability in "a page in the workarea folder" in Ektron CMS400.NET 7.00 through 7.04 and 7.50 through 7.52 has unknown impactektron · cms4000.net | Kritik10,0 | — | %1,4 | 6 Ağu 2008 |
30İzleyin | CVE-2008-5122İstismar yok | SQL injection vulnerability in WorkArea/ContentRatingGraph.aspx in Ektron CMS400.NET 7.5.2 and earlier allows remote attackers to execute arektron · cms4000.net · CWE-89 | Yüksek7,5 | — | %1,1 | 17 Kas 2008 |
28İzleyin | CVE-2015-0931İstismar yok | Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attacektron · ektron content management system · CWE-74 | Orta6,8 | — | %2,4 | 13 Şub 2015 |
27İzleyin | CVE-2015-0923Silahlaştırılmış | The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 beforektron · ektron content management system | Orta5,0 | — | %22,0 | 13 Şub 2015 |
24İzleyin | CVE-2015-3624Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content Management System (Cektron · ektron content management system · CWE-352 | Orta5,8 | — | %2,3 | 9 Haz 2015 |
24İzleyin | CVE-2016-6201İstismar yok | Cross-site scripting (XSS) vulnerability in Ektron Content Management System (CMS) before 9.1.0.184 SP3 (9.1.0.184.3.127) allows remote attaektron · ektron content management system · CWE-79 | Orta6,1 | — | %0,9 | 3 Tem 2017 |
24İzleyin | CVE-2016-6133İstismar yok | Cross-site scripting (XSS) vulnerability in Ektron Content Management System before 9.1.0.184SP3(9.1.0.184.3.127) allows remote attackers toektron · ektron content management system · CWE-79 | Orta6,1 | — | %0,8 | 25 Tem 2017 |
17İzleyin | CVE-2009-4473İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in WorkArea/ContentDesigner/ekformsiframe.aspx in Ektron CMS400.NET 7.6.1.53 and 7.6.6.4ektron · cms4000.net · CWE-79 | Orta4,3 | — | %1,2 | 30 Ara 2009 |
14İzleyin | CVE-2015-4427İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Test/WorkArea/workarea.aspx in Ektron Content Management System (CMS) before 9.10 SP1ektron · ektron content management system · CWE-79 | Düşük3,5 | — | %1,5 | 9 Haz 2015 |
14İzleyin | CVE-2014-2729İstismar yok | Cross-site scripting (XSS) vulnerability in content.aspx in Ektron CMS 8.7 before 8.7.0.055 allows remote authenticated users to inject arbiektron · ektron content management system · CWE-79 | Düşük3,5 | — | %1,0 | 25 Nis 2014 |
- CVE-2012-535759Planlayın
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remot
KritikCVSS 9,8SilahlaştırılmışEPSS %68ektron · ektron content management system30 Eki 2017
- CVE-2012-535840Planlayın
The XSLTCompiledTransform function in Ektron Content Management System (CMS) before 8.02 SP5 configures the XSL with enableDocumentFunction
KritikCVSS 9,8İstismar yokEPSS %2ektron · ektron content management system30 Eki 2017
- CVE-2008-349940Planlayın
Unspecified vulnerability in "a page in the workarea folder" in Ektron CMS400.NET 7.00 through 7.04 and 7.50 through 7.52 has unknown impact
KritikCVSS 10,0İstismar yokEPSS %1ektron · cms4000.net6 Ağu 2008
- CVE-2008-512230İzleyin
SQL injection vulnerability in WorkArea/ContentRatingGraph.aspx in Ektron CMS400.NET 7.5.2 and earlier allows remote attackers to execute ar
YüksekCVSS 7,5İstismar yokEPSS %1ektron · cms4000.net17 Kas 2008
- CVE-2015-093128İzleyin
Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attac
OrtaCVSS 6,8İstismar yokEPSS %2ektron · ektron content management system13 Şub 2015
- CVE-2015-092327İzleyin
The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 befor
OrtaCVSS 5,0SilahlaştırılmışEPSS %22ektron · ektron content management system13 Şub 2015
- CVE-2015-362424İzleyin
Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content Management System (C
OrtaCVSS 5,8Kavram kanıtıEPSS %2ektron · ektron content management system9 Haz 2015
- CVE-2016-620124İzleyin
Cross-site scripting (XSS) vulnerability in Ektron Content Management System (CMS) before 9.1.0.184 SP3 (9.1.0.184.3.127) allows remote atta
OrtaCVSS 6,1İstismar yokEPSS %1ektron · ektron content management system3 Tem 2017
- CVE-2016-613324İzleyin
Cross-site scripting (XSS) vulnerability in Ektron Content Management System before 9.1.0.184SP3(9.1.0.184.3.127) allows remote attackers to
OrtaCVSS 6,1İstismar yokEPSS %1ektron · ektron content management system25 Tem 2017
- CVE-2009-447317İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in WorkArea/ContentDesigner/ekformsiframe.aspx in Ektron CMS400.NET 7.6.1.53 and 7.6.6.4
OrtaCVSS 4,3İstismar yokEPSS %1ektron · cms4000.net30 Ara 2009
- CVE-2015-442714İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Test/WorkArea/workarea.aspx in Ektron Content Management System (CMS) before 9.10 SP1
DüşükCVSS 3,5İstismar yokEPSS %1ektron · ektron content management system9 Haz 2015
- CVE-2014-272914İzleyin
Cross-site scripting (XSS) vulnerability in content.aspx in Ektron CMS 8.7 before 8.7.0.055 allows remote authenticated users to inject arbi
DüşükCVSS 3,5İstismar yokEPSS %1ektron · ektron content management system25 Nis 2014