Ektron 8.5 / 8.7 / 9.0 XSLT Transform Remote Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 4 Mar 2017.

  1. Packet Storm

    Packet Storm Guest

    Ektron versions 8.5, 8.7 equal to and below sp1, and 9.0 before sp1 have vulnerabilities in various operations within the ServerControlWS.asmxweb services. These vulnerabilities allow for remote code execution without authentication and execute in the context of IIS on the remote system.

    Continue reading...
     

Share This Page

Loading...