Movable Type Unspecified Cross Site Scripting and Security Vulnerabilities
BID:47997
Info
Movable Type Unspecified Cross Site Scripting and Security Vulnerabilities
| Bugtraq ID: | 47997 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 26 2011 12:00AM |
| Updated: | May 26 2011 12:00AM |
| Credit: | Alfasado, Eldar Marcussen and unknown reporters. |
| Vulnerable: |
Movable Type Movable Type Pro 4.26 Movable Type Movable Type Pro 4.25 Movable Type Movable Type Pro 4.24 Movable Type Movable Type Pro 4 Movable Type Movable Type Open Source 5.04 Movable Type Movable Type Open Source 5.03 Movable Type Movable Type Open Source 4.35 Movable Type Movable Type Open Source 4.34 Movable Type Movable Type Open Source 4.26 Movable Type Movable Type Open Source 4.25 Movable Type Movable Type Open Source 4.24 Movable Type Movable Type Open Source 4.23 Movable Type Movable Type Open Source 4 Movable Type Movable Type Enterprise 4.35 Movable Type Movable Type Enterprise 4.34 Movable Type Movable Type Enterprise 4.26 Movable Type Movable Type Enterprise 4.25 Movable Type Movable Type Enterprise 4.24 Movable Type Movable Type Enterprise 4.23 Movable Type Movable Type Enterprise 4.22 Movable Type Movable Type Enterprise 4 Movable Type Movable Type Community Solution 4.26 Movable Type Movable Type Community Solution 4.25 Movable Type Movable Type Community Solution 4.24 Movable Type Movable Type Community Solution 4.23 Movable Type Movable Type Community Solution 4.22 Movable Type Movable Type Community Solution 4 Movable Type Movable Type Commercial 4.22 Movable Type Movable Type 5.04 Movable Type Movable Type 5.03 Movable Type Movable Type 5.02 Movable Type Movable Type 5.01 Movable Type Movable Type 5.0 Movable Type Movable Type 4.35 Movable Type Movable Type 4.34 Movable Type Movable Type 4.27 Movable Type Movable Type 4.261 Movable Type Movable Type 4.26 Movable Type Movable Type 4.25 Movable Type Movable Type 4.24 Movable Type Movable Type 4.23 Movable Type Movable Type 4.22 Movable Type Movable Type 4.21 Movable Type Movable Type 4.13 Movable Type Movable Type 4.01 Movable Type Movable Type 4 |
| Not Vulnerable: |
Movable Type Movable Type Open Source 5.05 Movable Type Movable Type Open Source 4.36 Movable Type Movable Type Enterprise 4.36 Movable Type Movable Type 5.05 Movable Type Movable Type 4.36 |
Discussion
Movable Type Unspecified Cross Site Scripting and Security Vulnerabilities
Movable Type is prone to a cross-site scripting vulnerability and an unspecified security vulnerability.
Attackers can leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Attackers can exploit the unspecified issue to read or modify content.
Very few details are available. We will update this BID as more information emerges.
Versions prior to Movable Type 4.36 and 5.05 are vulnerable.
Movable Type is prone to a cross-site scripting vulnerability and an unspecified security vulnerability.
Attackers can leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Attackers can exploit the unspecified issue to read or modify content.
Very few details are available. We will update this BID as more information emerges.
Versions prior to Movable Type 4.36 and 5.05 are vulnerable.
Exploit / POC
Movable Type Unspecified Cross Site Scripting and Security Vulnerabilities
To exploit the cross-site scripting issue, attackers must entice an unsuspecting user to follow a specially crafted URI.
To exploit the cross-site scripting issue, attackers must entice an unsuspecting user to follow a specially crafted URI.
Solution / Fix
Movable Type Unspecified Cross Site Scripting and Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Movable Type Unspecified Cross Site Scripting and Security Vulnerabilities
References:
References:
- Movable Type 5.05 and 4.36 Release Notes (Movable Type)
- Movable Type Homepage (Movable Type)