CVE-2015-4427 Information
Feb 14, 2021
cve
Description
Multiple cross-site scripting (XSS) vulnerabilities in Test/WorkArea/workarea.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.114) allow remote authenticated users to inject arbitrary web script or HTML via the (1) page (2) action (3) folder_id or (4) LangType parameter.
Reference
http://packetstormsecurity.com/files/132105/Ektron-CMS-9.10-SP1-Cross-Site-Scripting.html http://v00d00sec.com/2015/05/31/cve-2015-3624-csrf-and-xss-vulnerabilities-in-ektron-cms-9-10-sp1/ http://www.securityfocus.com/archive/1/535647/100/0/threaded http://www.securityfocus.com/bid/74942
Share on: