Show last authors
1 {{toc/}}
2
3 = Web (client side) =
4
5 |=Application|=XSLT Engine |=Vulnerabilities
6 |[[Webkit>>Application_Webkit]]|[[libxslt>>Engine_libxslt]]|File creation ([[CVE-2011-1774>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1774||rel="__blank" title="CVE-2011-1774"]])
7 |[[Firefox>>Application_Firefox]]|[[Transformiix>>Engine_Transformiix]]|Memory corruption ([[MFSA 2012-08>>http://www.mozilla.org/security/announce/2012/mfsa2012-08.html||rel="__blank" title="MFSA 2012-08"]] aka [[CVE-2012-0449>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0449||rel="__blank" title="CVE-2012-0449"]])\\
8 |[[Opera>>Application_Opera]] |[[Presto>>Engine_Presto]]|Misc crashes (DSK-355332 and DSK-355334)\\
9 |Internet Explorer|[[MS XML>>Engine_MSXML]]|\\
10
11 = Web (server side) =
12
13 |=Application|=XSLT Engine |=Vulnerabilities
14 |[[Liferay>>Application_Liferay]]|[[Xalan-J>>Engine_XalanJ]] |File disclosure ([[CVE-2011-1502>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1502||rel="__blank" title="CVE-2011-1502"]] and [[CVE-2011-1503>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1503||rel="__blank" title="CVE-2011-1503"]])
15 Code execution ([[CVE-2011-1571>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1571||rel="__blank" title="CVE-2011-1571"]])
16 |[[PHP 5>>Application_PHP5]]|[[libxslt>>Engine_libxslt]]|Arbitrary file creation ([[CVE-2012-0057>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0057||rel="__blank" title="CVE-2012-0057"]], corrected in v5.3.9)
17 |[[Sharepoint>>Application_Sharepoint]]|[[MS XML>>Engine_MSXML]]|XML External Entity : File disclosure, ... ([[CVE-2011-1892>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1892||rel="__blank" title="CVE-2011-1892"]] aka [[MS11-074>>http://technet.microsoft.com/security/bulletin/MS11-074||rel="__blank" title="MS11-074"]])
18 |[[DotNetNuke>>Application_DotNetNuke]]|[[MS XML>>Engine_MSXML]]|XML External Entity : File disclosure, ... (No CVE, patched in v06.00.00 of the XML module)
19 |[[MoinMoin>>Application_MoinMoin]]|[[4Suite>>Engine_4Suite]]|Arbitrary file disclosure and creation ([[CVE-2012-xxxx>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-xxxx||rel="__blank" title="CVE-2012-xxxx"]])
20
21 = Online services =
22
23 |=Application |=XSLT engine
24 | [[W3C XSLT Gateway>>http://www.w3.org/2005/08/online_xslt/]] | [[Saxon>>Engine_Saxon]]
25 | [[Online Toolz>>http://online-toolz.com/tools/xslt-transformation.php]]|[[ libxslt>>Engine_libxslt]]
26 | [[Shell Tools>>http://www.shell-tools.net/index.php?op=xslt]]| [[libxslt>>Engine_libxslt]]
27 | [[XSLT Java applet>>http://unindented.org/projects/xslt-tester-applet/]]| XSLTC from [[Xalan-J>>Engine_XalanJ]]
28
29 = Office software =
30
31 |=Application|=XSLT Engine |=Vulnerabilities
32 |Adobe Reader|Modified [[Sablotron>>Engine_Sablotron]] |Memory corruption (Linux only)
33 |Lifera|[[libxslt>>Engine_libxslt]]|File creation
34 |OpenOffice|[[libxslt>>Engine_libxslt]]|\\
35
36 = Security =
37
38 |=Application|=XSLT Engine |=Vulnerabilities
39 |[[xmlsec>>Application_xmlsec]]|[[libxslt>>Engine_libxslt]]|File creation ([[CVE-2011-1425>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1425||rel="__blank" title="CVE-2011-1425"]])
40 |Lasso|[[libxslt>>Engine_libxslt]]|\\
41 |Unnamed application verifying XML-DSig signatures|[[Xalan-J>>Engine_XalanJ]]|Remote code execution
42
43 = Databases =
44
45 |=Application|=XSLT Engine |=Vulnerabilities
46 |Postgres SQL|[[libxslt>>Engine_libxslt]]|File disclosure, File creation

Welcome

Welcome on the XSLT Hacking Encyclopedia !

You may be interested by the Engines and Applications pages.

Link to the blog
Twitter: @Agarri_FR

Tag Cloud

Unknown macro: tagcloud. Click on this message for details.

Content by Nicolas Grégoire / Agarri
Blog - Follow me @Agarri_FR