4.3
CVSSv2

CVE-2014-0977

Published: 10/01/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Rich Text Editor in Movable Type 5.0x, 5.1x prior to 5.161, 5.2.x prior to 5.2.9, and 6.0.x prior to 6.0.1 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

sixapart movabletype 5.11

sixapart movabletype 5.12

sixapart movabletype 5.2.7

sixapart movabletype 6.0

sixapart movabletype 5.15

sixapart movabletype 5.2

sixapart movabletype 5.2.2

sixapart movabletype 5.02

sixapart movabletype 5.01

sixapart movabletype 5.04

sixapart movabletype 5.2.3

sixapart movabletype 5.2.6

sixapart movabletype 5.0

sixapart movabletype 5.13

sixapart movabletype 5.14

sixapart movabletype 5.031

sixapart movabletype 5.03

Vendor Advisories

A cross-site scripting vulnerability was discovered in the rich text editor of the Movable Type blogging engine For the oldstable distribution (squeeze), this problem has been fixed in version 438+dfsg-0+squeeze4 For the stable distribution (wheezy), this problem has been fixed in version 514+dfsg-4+deb7u1 For the unstable distribution (sid) ...