The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference within an XML document named in the xslt parameter, related to an XML External Entity (XXE) issue.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2015-02-14T02:00:00

Updated: 2024-08-06T04:26:11.452Z

Reserved: 2015-01-10T00:00:00

Link: CVE-2015-0923

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2015-02-14T03:01:17.927

Modified: 2015-02-17T17:11:49.160

Link: CVE-2015-0923

cve-icon Redhat

No data.