[Japanese]
|
JVNDB-2011-000031
|
Movable Type vulnerable to cross-site scripting
|
Movable Type contains a cross-site scripting vulnerability.
Movable Type, a web log system from Six Apart KK, contains a cross-site scripting vulnerability due to an issue in the management screen.
This vulnerability is different than the previous vulnerabilities disclosed on JVN.
Takeshi Terada of Mitsui Bussan Secure Directions reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendor under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 5.0 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
|
Six Apart, Ltd.
- Movable Type 4.21 and earlier
- Movable Type (community_solution) 4.21 and earlier
- Movable Type (enterprise) 4.21 and earlier
- Movable Type Open Source 4.21 and earlier
|
|
An arbitrary script may be executed on the user's web browser.
|
[Update the Software]
Update to the latest version according to the information provided by the developer.
|
Six Apart, Ltd.
|
- Cross-site Scripting(CWE-79) [IPA Evaluation]
|
- CVE-2008-5845
|
- JVN : JVN#45658190
- National Vulnerability Database (NVD) : CVE-2008-5845
|
- [2011/05/25]
Web page published
|