First published: Fri Sep 29 2006(Updated: )
Cross-site scripting (XSS) vulnerability in the search function in Six Apart Movable Type 3.3 to 3.32, and Movable Type Enterprise 1.01 and 1.02, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Movable Type | =3.3 | |
Movable Type | =enterprise_1.02 | |
Movable Type | =enterprise_1.01 | |
Movable Type | =3.32 | |
=3.3 | ||
=3.32 | ||
=enterprise_1.01 | ||
=enterprise_1.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5080 is classified as a high severity vulnerability due to its potential for allowing arbitrary web script injection.
To fix CVE-2006-5080, upgrade to Movable Type version 3.33 or later or Movable Type Enterprise version 1.03 or later.
CVE-2006-5080 affects Six Apart Movable Type versions 3.3 to 3.32 and Movable Type Enterprise versions 1.01 and 1.02.
CVE-2006-5080 is a cross-site scripting (XSS) vulnerability that allows attackers to inject scripts into web pages.
Yes, CVE-2006-5080 can be exploited remotely by attackers to execute arbitrary scripts.