RETIRED: Movable Type A-Form Plugins Cross Site Scripting and Unspecified Security Vulnerabilities
BID:50017
Info
RETIRED: Movable Type A-Form Plugins Cross Site Scripting and Unspecified Security Vulnerabilities
| Bugtraq ID: | 50017 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 07 2011 12:00AM |
| Updated: | Nov 04 2011 04:03PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
ARK-Web A-Form PC/Mobile 3.0 ARK-Web A-Form PC 3.0 ARK-Web A-Form Bamboo 2.0.2 ARK-Web A-Form Bamboo 1.3.5 ARK-Web A-Form 2.0.2 ARK-Web A-Form 1.3.5 |
| Not Vulnerable: |
ARK-Web A-Form PC/Mobile 3.1 ARK-Web A-Form PC 3.1 ARK-Web A-Form Bamboo 2.0.3 ARK-Web A-Form Bamboo 1.3.6 ARK-Web A-Form 2.0.3 ARK-Web A-Form 1.3.6 |
Exploit / POC
RETIRED: Movable Type A-Form Plugins Cross Site Scripting and Unspecified Security Vulnerabilities
To exploit the cross-site scripting issue, attackers must entice an unsuspecting user to follow a specially crafted URI.
To exploit the cross-site scripting issue, attackers must entice an unsuspecting user to follow a specially crafted URI.
Solution / Fix
RETIRED: Movable Type A-Form Plugins Cross Site Scripting and Unspecified Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
RETIRED: Movable Type A-Form Plugins Cross Site Scripting and Unspecified Security Vulnerabilities
References:
References:
- 1.3.6,2.0.3,3.1 security patch application procedure (ARK-Web)
- Movable Type Homepage (Movable Type)
- Vendor Homepage (ark-web)