Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote attackers to take control of sessions via unspecified vectors related to the (1) commenting feature and (2) community script.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Movable_type | Sixapart | * | 4.37 (including) |
Movable_type | Sixapart | 4.28 (including) | 4.28 (including) |
Movable_type | Sixapart | 4.29 (including) | 4.29 (including) |
Movable_type | Sixapart | 4.36 (including) | 4.36 (including) |
Movable_type | Sixapart | 4.291 (including) | 4.291 (including) |
Movable_type | Sixapart | 4.292 (including) | 4.292 (including) |
Movable_type | Sixapart | 4.361 (including) | 4.361 (including) |
Movable_type | Sixapart | 5.0 (including) | 5.0 (including) |
Movable_type | Sixapart | 5.01 (including) | 5.01 (including) |
Movable_type | Sixapart | 5.1 (including) | 5.1 (including) |
Movable_type | Sixapart | 5.02 (including) | 5.02 (including) |
Movable_type | Sixapart | 5.04 (including) | 5.04 (including) |
Movable_type | Sixapart | 5.05 (including) | 5.05 (including) |
Movable_type | Sixapart | 5.06 (including) | 5.06 (including) |
Movable_type | Sixapart | 5.11 (including) | 5.11 (including) |
Movable_type | Sixapart | 5.12 (including) | 5.12 (including) |
Movable_type | Sixapart | 5.051 (including) | 5.051 (including) |
Movabletype-opensource | Ubuntu | lucid | * |
Movabletype-opensource | Ubuntu | maverick | * |
Movabletype-opensource | Ubuntu | natty | * |
Movabletype-opensource | Ubuntu | oneiric | * |
Movabletype-opensource | Ubuntu | precise | * |
Movabletype-opensource | Ubuntu | upstream | * |