Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Movable Type < 5.02 Multiple Vulnerabilities

Medium

Synopsis

The remote host is vulnerable to a cross-Site scripting (XSS) attack

Description

The remote host is running Movable Type, a blogging software for Unix and Windows platforms. The installed version is earlier than 5.02. Such versions are reportedly affected by a cross-site scripting flaw. An attacker, exploiting this flaw, would be able to post script code which would be executed in the browser of the blog readers.

Solution

Upgrade to Movable Type 5.02 or later.