7 results (0.010 seconds)

CVSS: 6.1EPSS: 0%CPEs: 4EXPL: 0

Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors. Una vulnerabilidad de tipo cross-site scripting en la pantalla de activo Add del campo Contents de Movable Type 7 r.4705 y anteriores (Movable Type 7 Series), Movable Type Advanced 7 r.4705 y anteriores (Movable Type Advanced 7 Series), Movable Type Premium versiones 1.39 y anteriores, y Movable Type Premium Advanced versiones 1.39 y anteriores, permiten a atacantes remotos inyectar un script arbitrario por medio de vectores no especificados • https://jvn.jp/en/jp/JVN66542874/index.html https://movabletype.org/news/2021/02/mt-760-676-released.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 5EXPL: 0

Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type 6.7.5 and earlier (Movable Type 6.7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors. Una vulnerabilidad de tipo cross-site scripting en la pantalla de registro Asset de Movable Type 7 r.4705 y anteriores (Movable Type 7 Series), Movable Type Advanced 7 r.4705 y anteriores (Movable Type Advanced 7 Series), Movable Type versiones 6.7.5 y anteriores (Movable Type 6.7 Series), Movable Type Premium versiones 1.39 y anteriores, y Movable Type Premium Advanced versiones 1.39 y anteriores, permiten a atacantes remotos inyectar script arbitrario por medio de vectores no especificados • https://jvn.jp/en/jp/JVN66542874/index.html https://movabletype.org/news/2021/02/mt-760-676-released.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 5EXPL: 0

Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type 6.7.5 and earlier (Movable Type 6.7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors. Una vulnerabilidad de tipo cross-site scripting en la pantalla de configuración de autoridad Role de Movable Type 7 r.4705 y anteriores (Movable Type 7 Series), Movable Type Advanced 7 r.4705 y anteriores (Movable Type Advanced 7 Series), Movable Type versiones 6.7.5 y anteriores (Movable Type 6.7 Series), Movable Type Premium versiones 1.39 y anteriores, y Movable Type Premium Advanced versiones 1.39 y anteriores, permiten a atacantes remotos inyectar script arbitrario por medio de vectores no especificados • https://jvn.jp/en/jp/JVN66542874/index.html https://movabletype.org/news/2021/02/mt-760-676-released.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 120EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to inject arbitrary web script or HTML via vectors involving templates, a different issue than CVE-2012-1262. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Movable Type anteriores a 4.38, 5.0x anteriores 5.07, y 5.1x anteriores a 5.13 permiten a atacantes remotos inyectar codigo de script web o código HTML de su elección a través de vectores relacionados con plantillas ("templates"), una vulnerabilidad distinta a la CVE-2012-1262. • http://jvn.jp/en/jp/JVN49836527/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2012-000016 http://www.debian.org/security/2012/dsa-2423 http://www.movabletype.org/2012/02/movable_type_513_507_and_438_security_updates.html http://www.movabletype.org/documentation/appendices/release-notes/513.html http://www.securityfocus.com/bid/52138 http://www.securitytracker.com/id?1026738 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.0EPSS: 0%CPEs: 120EXPL: 0

The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files by leveraging the template-designer role. La configuración por defecto de Movable Type anteriores a 4.38, 5.0x y 5.07, y 5.1x anteriores 5.13 soporta el atributo "mt:Include file=", lo que permite a usuarios autenticados remotos realizar ataques de salto de directorio y leer archivos arbitrarios utilizando el perfil "template-designer". • http://www.debian.org/security/2012/dsa-2423 http://www.movabletype.org/2012/02/movable_type_513_507_and_438_security_updates.html http://www.movabletype.org/documentation/appendices/release-notes/513.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •