CVE-2011-4274: XSS
Published Nov 3, 2011
·Updated
Cross-site scripting (XSS) vulnerability in the A-Form PC and PC/Mobile before 3.1 plug-ins for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-2676.
Affected Software
3 affected components
Ark-web A-form Pc<=3.0
Ark-web A-form Pc Mobile<=3.0
Sixapart Movabletype
Remediation
Event History
Nov 3, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
10:55 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-4274?
CVE-2011-4274 is classified as a cross-site scripting (XSS) vulnerability which can allow attackers to inject malicious scripts.
2
How do I fix CVE-2011-4274?
To remediate CVE-2011-4274, update the A-Form PC and PC/Mobile plug-ins to version 3.1 or higher.
3
What software is affected by CVE-2011-4274?
CVE-2011-4274 affects A-Form PC and A-Form PC/Mobile versions prior to 3.1.
4
Can CVE-2011-4274 be exploited remotely?
Yes, CVE-2011-4274 can be exploited remotely by attackers through unspecified vectors.
5
Is there a patch available for CVE-2011-4274?
Yes, a security patch is available that addresses CVE-2011-4274 in A-Form PC and PC/Mobile.