First published: Thu Nov 03 2011(Updated: )
Cross-site scripting (XSS) vulnerability in the A-Form PC and PC/Mobile before 3.1 plug-ins for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-2676.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ark-web A-Form | <=3.0 | |
ark-web A-Form | <=3.0 | |
Six Apart Movable Type |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4274 is classified as a cross-site scripting (XSS) vulnerability which can allow attackers to inject malicious scripts.
To remediate CVE-2011-4274, update the A-Form PC and PC/Mobile plug-ins to version 3.1 or higher.
CVE-2011-4274 affects A-Form PC and A-Form PC/Mobile versions prior to 3.1.
Yes, CVE-2011-4274 can be exploited remotely by attackers through unspecified vectors.
Yes, a security patch is available that addresses CVE-2011-4274 in A-Form PC and PC/Mobile.