icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons_061

Movable Type < 5.02 Multiple Vulnerabilities

Medium

Synopsis

The remote host is vulnerable to a cross-Site scripting (XSS) attack

Description

The remote host is running Movable Type, a blogging software for Unix and Windows platforms. The installed version is earlier than 5.02. Such versions are reportedly affected by a cross-site scripting flaw. An attacker, exploiting this flaw, would be able to post script code which would be executed in the browser of the blog readers.

Solution

Upgrade to Movable Type 5.02 or later.