Movable Type Unspecified Cross-Site Scripting Vulnerability
BID:20228
Info
Movable Type Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 20228 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2006 12:00AM |
| Updated: | Nov 23 2006 08:06PM |
| Credit: | Arai is credited with the discovery of this vulnerability. |
| Vulnerable: |
Movable Type Movable Type Enterprise 1.02 Movable Type Movable Type Enterprise 1.01 Movable Type Movable Type 3.32 Movable Type Movable Type 3.31 Movable Type Movable Type 3.3 |
| Not Vulnerable: |
Movable Type Movable Type Enterprise 1.03 Movable Type Movable Type 3.33 |
Discussion
Movable Type Unspecified Cross-Site Scripting Vulnerability
Movable Type is prone to an unspecified cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Movable Type versions 3.3, 3.31, 3.32 and Movable Type Enterprise 1.01 and 1.02 are confirmed vulnerable to this issue.
Movable Type is prone to an unspecified cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Movable Type versions 3.3, 3.31, 3.32 and Movable Type Enterprise 1.01 and 1.02 are confirmed vulnerable to this issue.
Exploit / POC
Movable Type Unspecified Cross-Site Scripting Vulnerability
An attacker may exploit this issue by enticing a victim user into following a malicious link.
An attacker may exploit this issue by enticing a victim user into following a malicious link.
Solution / Fix
Movable Type Unspecified Cross-Site Scripting Vulnerability
Solution:
The vendor released version 3.33 and Enterprise version 1.03 to address this issue. Please see the references section for further information.
Solution:
The vendor released version 3.33 and Enterprise version 1.03 to address this issue. Please see the references section for further information.
References
Movable Type Unspecified Cross-Site Scripting Vulnerability
References:
References:
- JP Vendor Status Notes (JVN)
- Movable Type 3.33/MT Enterprise 1.03 released (Movable Type)
- Movable Type Home Page (Six Apart)