Movable Type Pro
Movabletype · 4 CVEs
CVE-2012-1497
MEDIUM
The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include…
Mar 3, 2012
CVE-2012-1262
MEDIUM
Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and…
Mar 3, 2012
CVE-2012-0319
MEDIUM
The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authentica…
Mar 3, 2012
CVE-2012-0318
MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13…
Mar 3, 2012
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2012-1497 | The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, which allows remote au… | MEDIUM | 1.85% | Mar 3, 2012 |
| CVE-2012-1262 | Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, when the product is i… | MEDIUM | 1.90% | Mar 3, 2012 |
| CVE-2012-0319 | The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute arbitrary commands… | MEDIUM | 2.42% | Mar 3, 2012 |
| CVE-2012-0318 | Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to inject arbitr… | MEDIUM | 1.34% | Mar 3, 2012 |
Showing 1 to 4 of 4 CVEs