CVE-2007-6751: XSS
Published Jan 4, 2012
·Updated
Cross-site scripting (XSS) vulnerability in the MailForm plugin before 1.20 for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
7 affected components
H-fj Mailform Plugin<=1.11
H-fj Mailform Plugin=1.00
H-fj Mailform Plugin=1.10
Sixapart Movable Type=4.0
Sixapart Movable Type=4.0
Sixapart Movable Type=4.1
Sixapart Movable Type=4.1
Remediation
Patch Available
Event History
Jan 4, 2012
CVE Published
07:55 PM
Data Sourced
07:55 PM
DescriptionWeaknessAffected Software
Jan 5, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6751?
CVE-2007-6751 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2007-6751?
To fix CVE-2007-6751, update the MailForm plugin to version 1.20 or later.
3
What types of attacks can be executed via CVE-2007-6751?
CVE-2007-6751 allows remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web script or HTML.
4
Which software versions are affected by CVE-2007-6751?
CVE-2007-6751 affects MailForm plugin versions before 1.20, specifically 1.00 through 1.11.
5
Is Movable Type directly affected by CVE-2007-6751?
No, Movable Type versions 4.0 and 4.1 are not directly affected by CVE-2007-6751 if they do not use the vulnerable MailForm plugin.