|
[Japanese]
|
JVNDB-2007-000073
|
Movable Type cross-site scripting vulnerability
|
Movable Type, a web log system from Six Apart, contains a cross-site scripting vulnerability.
This vulnerability is different from JVN#68295640.
|
Base Metrics:
5.0 (Medium)
[IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
|
|
Six Apart
- Movable Type 3.3-ja
- Movable Type 3.31-ja
- Movable Type 3.32-ja
- Movable Type 3.33-ja
|
|
An arbitrary script could be executed on the user's web browser or the display of a web page could be falsified. In addition, an attacker may be able to access a user's cookie allowing them to view sensitive information or hijack an authenticated user's session.
|
|
Six Apart
|
|
|
- JVN : JVN#32985115
|
[2008/05/21]
Web page published
|