| [Japanese] | 
| JVNDB-2011-000031 | 
| Movable Type vulnerable to cross-site scripting | 
|
| 
 
Movable Type contains a cross-site scripting vulnerability.
 Movable Type, a web log system from Six Apart KK, contains a cross-site scripting vulnerability due to an issue in the management screen.
 
 This vulnerability is different than the previous vulnerabilities disclosed on JVN.
 
 Takeshi Terada of Mitsui Bussan Secure Directions reported this vulnerability to IPA.
 JPCERT/CC coordinated with the vendor under Information Security Early Warning Partnership.
 | 
|
| 
 
  CVSS V2 Severity:Base Metrics 5.0 (Medium) [IPA Score]
 
    Access Vector: NetworkAccess Complexity: LowAuthentication: NoneConfidentiality Impact: NoneIntegrity Impact: PartialAvailability Impact: None 
  
 | 
|
| 
 
	
 | 
| 
 
	Six Apart, Ltd.
	
		Movable Type 4.21 and earlierMovable Type (community_solution) 4.21 and earlierMovable Type (enterprise) 4.21 and earlierMovable Type Open Source 4.21 and earlier | 
| 
 
	
 | 
|
| 
 
An arbitrary script may be executed on the user's web browser.
 | 
|
| 
 
[Update the Software]Update to the latest version according to the information provided by the developer.
 | 
|
| 
 
	Six Apart, Ltd.
	
 | 
|
| 
 
	Cross-site Scripting(CWE-79) [IPA Evaluation] | 
|
| 
 
	CVE-2008-5845  | 
|
| 
 
	JVN : JVN#45658190 National Vulnerability Database (NVD) : CVE-2008-5845  | 
|
| 
 
	[2011/05/25]Web page published
 
 |