OSVDB ID: 29177

Title: Movable Type Search Function Unspecified XSS

Info

Disclosure

Sep 26, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Movable Type contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecififed variables upon submission to the search function. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
OSVDB: Web Related

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, vendor has released a patch to address this vulnerability.

Products

Six Apart, Ltd.

Movable Type

3.3
3.31
3.32

Movable Type Enterprise

1.01
1.02

References

Credit

  • Arai -


Direct URL: http://osvdb.org/29177