Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.902402
Categoría:Web application abuses
Título:Movable Type Multiple Vulnerabilities (Apr 2011)
Resumen:Movable Type is prone to multiple vulnerabilities.
Descripción:Summary:
Movable Type is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws are caused by input validation errors related to
'mt:AssetProperty' and 'mt:EntryFlag' tags and in dynamic publishing error messages, which could
be exploited to conduct SQL injection (SQLi) or cross-site scripting (XSS) attacks.

Vulnerability Impact:
Successful exploitation will allow attackers to gain knowledge
of sensitive information or inject SQL queries.

Affected Software/OS:
Movable Type version 4.x prior to 4.35 and 5.x prior to
5.04

Solution:
Update to version 4.35, 5.04 or later.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2010-3921
http://jvn.jp/en/jp/JVN36673836/index.html
http://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000060.html
http://www.securitytracker.com/id?1024833
http://secunia.com/advisories/42539
http://www.vupen.com/english/advisories/2010/3145
Common Vulnerability Exposure (CVE) ID: CVE-2010-3922
http://jvn.jp/en/jp/JVN78536512/index.html
http://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000061.html
Common Vulnerability Exposure (CVE) ID: CVE-2010-4509
BugTraq ID: 45383
http://www.securityfocus.com/bid/45383
XForce ISS Database: movable-type-multiple-unspec(64130)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64130
Common Vulnerability Exposure (CVE) ID: CVE-2010-4511
BugTraq ID: 45380
http://www.securityfocus.com/bid/45380
http://osvdb.org/69751
XForce ISS Database: movable-type-unspecified(64129)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64129
CopyrightCopyright (C) 2011 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.