First published: Fri Jan 02 2009(Updated: )
Cross-site scripting (XSS) vulnerability in Six Apart Movable Type Enterprise (MTE) 1.x before 1.56; Movable Type (MT) 3.x before 3.38; and Movable Type, Movable Type Open Source (MTOS), and Movable Type Enterprise 4.x before 4.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to "application management."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Movable Type | =4 | |
Movable Type | =4-unknown | |
Movable Type | =4-unknown | |
Movable Type | =4.20 | |
Movable Type | =4.20-unknown | |
Movable Type | =4.20-unknown | |
Six Apart Movable Type | =1.00 | |
Six Apart Movable Type | =1.1 | |
Six Apart Movable Type | =1.2 | |
Six Apart Movable Type | =1.3 | |
Six Apart Movable Type | =1.4 | |
Six Apart Movable Type | =1.5 | |
Six Apart Movable Type | =1.31 | |
Six Apart Movable Type | =3.0d | |
Six Apart Movable Type | =3.1 | |
Six Apart Movable Type | =3.01d | |
Six Apart Movable Type | =3.2 | |
Six Apart Movable Type | =3.3 | |
Six Apart Movable Type | =3.11 | |
Six Apart Movable Type | =3.12 | |
Six Apart Movable Type | =3.14 | |
Six Apart Movable Type | =3.15 | |
Six Apart Movable Type | =3.16 | |
Six Apart Movable Type | =3.17 | |
Six Apart Movable Type | =3.32 | |
Six Apart Movable Type | =3.33 | |
Six Apart Movable Type | =3.34 | |
Six Apart Movable Type | =3.35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5808 has been classified as a high severity cross-site scripting vulnerability.
To fix CVE-2008-5808, upgrade Movable Type to version 1.56 or later for MTE, or 3.38 or later for MT 3.x, or 4.23 or later for MT 4.x.
CVE-2008-5808 affects Six Apart Movable Type Enterprise 1.x before 1.56, Movable Type 3.x before 3.38, and Movable Type 4.x before 4.23.
CVE-2008-5808 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML.
Yes, if exploited, CVE-2008-5808 could allow remote attackers to steal sensitive information from unsuspecting users.