CVE-2007-0231: XSS
Published Jan 13, 2007
·Updated
Cross-site scripting (XSS) vulnerability in Movable Type (MT) 3.33, when nofollow is disabled and unmoderated comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Comments field.
Affected Software
1 affected component
Six Apart Movable Type=3.33
Event History
Jan 13, 2007
CVE Published
02:28 AM
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0231?
CVE-2007-0231 is considered a moderate severity cross-site scripting vulnerability.
2
How do I fix CVE-2007-0231?
To fix CVE-2007-0231, ensure that nofollow is enabled and moderate comments before they are published.
3
What software is affected by CVE-2007-0231?
CVE-2007-0231 affects Movable Type version 3.33.
4
Can CVE-2007-0231 be exploited remotely?
Yes, CVE-2007-0231 can be exploited remotely if unmoderated comments are enabled.
5
What types of attacks can occur due to CVE-2007-0231?
CVE-2007-0231 allows attackers to inject arbitrary web scripts or HTML via the Comments field.