Check Point Reference: | CPAI-2013-1910 |
Date Published: | 21 Jul 2013 |
Severity: | High |
Last Updated: | Tuesday 07 January, 2025 |
Source: | CVE-2012-5357 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | Ektron CMS. |
Vulnerability Description | A remote code execution vulnerability has been reported in Ektron CMS in XslCompiledTransform class. |
Vulnerability Details | The vulnerability exists due to the insecure usage of XslCompiledTransform, using a XSLT controlled by the user. Successful exploitation attempt would allow an attacker to take complete control of the target system. |
This protection will detect and block attempts to exploit this vulnerability.
In order for the protection to be activated, update your product to the latest update. For information on how to update , go to SBP-2006-05, Protection tab and select the version of your choice.
SmartView Tracker will log the following entries:
Attack Name: Application Servers Protection Violation
Attack Information: Ektron 8.02 XSLT Transform Remote Code Execution