Show filters
61 Total Results
Displaying 51-60 of 61
Sort by:
Attacker Value
Unknown
CVE-2008-4634
Disclosure Date: October 21, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Movable Type 4 through 4.21 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the administrative page, a different vulnerability than CVE-2008-4079.
0
Attacker Value
Unknown
CVE-2008-4079
Disclosure Date: September 15, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Movable Type (MT) 4.x through 4.20, and 3.36 and earlier; Movable Type Enterprise 4.x through 4.20, and 1.54 and earlier; and Movable Type Community Solution allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-3342
Disclosure Date: June 21, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Movable Type (MT) before 3.34 allow remote attackers to inject arbitrary web script or HTML via comments that have (1) a malformed SGML numeric character reference with a '\0' (0x00) character in a javascript: URI or (2) an attribute in an element that lacks the '>' character at the end of the start tag, a different vulnerability than CVE-2007-0231.
0
Attacker Value
Unknown
CVE-2007-0604
Disclosure Date: January 30, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Movable Type (MT) before 3.34 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the MTCommentPreviewIsStatic tag, which can open the "comment entry screen," a different vulnerability than CVE-2007-0231.
0
Attacker Value
Unknown
CVE-2007-0231
Disclosure Date: January 13, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Movable Type (MT) 3.33, when nofollow is disabled and unmoderated comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Comments field.
0
Attacker Value
Unknown
CVE-2006-5080
Disclosure Date: September 29, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the search function in Six Apart Movable Type 3.3 to 3.32, and Movable Type Enterprise 1.01 and 1.02, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2005-4690
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Six Apart Movable Type 3.16 allows local users with blog-creation privileges to create or overwrite arbitrary files of certain types (such as HTML and image files) by selecting an arbitrary directory as a blog's top-level directory. NOTE: this issue can be used in conjunction with CVE-2005-3102 to create or overwrite arbitrary files of all types.
0
Attacker Value
Unknown
CVE-2005-3104
Disclosure Date: September 28, 2005 (last updated February 22, 2025)
mt-comments.cgi in Movable Type before 3.2 allows attackers to redirect users to other web sites via URLs in comments.
0
Attacker Value
Unknown
CVE-2005-3101
Disclosure Date: September 28, 2005 (last updated February 22, 2025)
The password reset feature in Movable Type before 3.2 generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.
0
Attacker Value
Unknown
CVE-2005-3103
Disclosure Date: September 28, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Movable Type before 3.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title, (2) category, (3) body, (4) extended body, and (5) excerpt form fields in new blog entries.
0