First published: Sat Mar 03 2012(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to hijack the authentication of arbitrary users for requests that modify data via the (1) commenting feature or (2) community script.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Sixapart Movable Type | <=4.37 | |
Sixapart Movable Type | =4.28 | |
Sixapart Movable Type | =4.29 | |
Sixapart Movable Type | =4.36 | |
Sixapart Movable Type | =4.291 | |
Sixapart Movable Type | =4.292 | |
Sixapart Movable Type | =4.361 | |
Sixapart Movable Type | =5.0 | |
Sixapart Movable Type | =5.01 | |
Sixapart Movable Type | =5.1 | |
Sixapart Movable Type | =5.02 | |
Sixapart Movable Type | =5.04 | |
Sixapart Movable Type | =5.05 | |
Sixapart Movable Type | =5.06 | |
Sixapart Movable Type | =5.11 | |
Sixapart Movable Type | =5.12 | |
Sixapart Movable Type | =5.051 | |
Sixapart Movable Type | <=4.292 | |
Sixapart Movable Type | =4.28 | |
Sixapart Movable Type | =4.29 | |
Sixapart Movable Type | =4.291 | |
Sixapart Movable Type | =5.1 | |
Sixapart Movable Type | =5.02 | |
Sixapart Movable Type | =5.04 | |
Sixapart Movable Type | =5.05 | |
Sixapart Movable Type | =5.06 | |
Sixapart Movable Type | =5.11 | |
Sixapart Movable Type | =5.12 | |
Sixapart Movable Type | =5.051 | |
Sixapart Movable Type | =4.0 | |
Sixapart Movable Type | =4.0-beta | |
Sixapart Movable Type | =4.0-beta2 | |
Sixapart Movable Type | =4.0-beta3 | |
Sixapart Movable Type | =4.0-beta4 | |
Sixapart Movable Type | =4.0-beta5 | |
Sixapart Movable Type | =4.0-beta6 | |
Sixapart Movable Type | =4.0-beta7 | |
Sixapart Movable Type | =4.0-rc1 | |
Sixapart Movable Type | =4.0-rc2 | |
Sixapart Movable Type | =4.0-rc3 | |
Sixapart Movable Type | =4.1-beta | |
Sixapart Movable Type | =4.1-beta2 | |
Sixapart Movable Type | =4.1-rc1 | |
Sixapart Movable Type | =4.2 | |
Sixapart Movable Type | =4.2-rc2 | |
Sixapart Movable Type | =4.2-rc4 | |
Sixapart Movable Type | =4.2-rc5 | |
Sixapart Movable Type | =4.12 | |
Sixapart Movable Type | =4.15-beta1 | |
Sixapart Movable Type | =4.15-beta3 | |
Sixapart Movable Type | =4.15-beta4 | |
Sixapart Movable Type | =4.22 | |
Sixapart Movable Type | =4.23 | |
Sixapart Movable Type | =4.24 | |
Sixapart Movable Type | =4.25 | |
Sixapart Movable Type | =4.26 | |
Sixapart Movable Type | =4.27 | |
Sixapart Movable Type | =4.28 | |
Sixapart Movable Type | =4.29 | |
Sixapart Movable Type | =4.35 | |
Sixapart Movable Type | =4.36 | |
Sixapart Movable Type | =4.37 | |
Sixapart Movable Type | =4.261 | |
Sixapart Movable Type | =4.291 | |
Sixapart Movable Type | =4.292 | |
Sixapart Movable Type | =4.361 | |
Sixapart Movable Type | =5.0 | |
Sixapart Movable Type | =5.0-beta1 | |
Sixapart Movable Type | =5.0-beta2 | |
Sixapart Movable Type | =5.0-beta3 | |
Sixapart Movable Type | =5.0-beta4 | |
Sixapart Movable Type | =5.0-rc1 | |
Sixapart Movable Type | =5.0-rc2 | |
Sixapart Movable Type | =5.0-rc3 | |
Sixapart Movable Type | =5.01 | |
Sixapart Movable Type | =5.1-beta | |
Sixapart Movable Type | =5.1-rc1 | |
Sixapart Movable Type | =5.02 | |
Sixapart Movable Type | =5.03 | |
Sixapart Movable Type | =5.04 | |
Sixapart Movable Type | =5.05 | |
Sixapart Movable Type | =5.06 | |
Sixapart Movable Type | =5.07 | |
Sixapart Movable Type | =5.11 | |
Sixapart Movable Type | =5.12 | |
Sixapart Movable Type | =5.031 | |
Sixapart Movable Type | =5.051 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.