First published: Wed May 14 2003(Updated: )
Cross-site scripting (XSS) vulnerability in Movable Type before 2.6, and possibly other versions including 2.63, allows remote attackers to insert arbitrary web script or HTML via the Name textbox, possibly when the "Allow HTML in comments?" option is enabled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Six Apart Movable Type | =2.63 | |
Six Apart Movable Type | <=2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.