First published: Sat Jul 07 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the MT4i plugin 3.1 beta 4 and earlier for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-2642.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
hazama MT4i | <=3.1 | |
Movable Type |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2644 is categorized as a cross-site scripting (XSS) vulnerability, which can allow attackers to inject malicious scripts into web pages.
To fix CVE-2012-2644, update the MT4i plugin to a version later than 3.1 beta 4, where the vulnerability has been addressed.
CVE-2012-2644 affects MT4i plugin version 3.1 beta 4 and earlier.
CVE-2012-2644 can facilitate various attacks, including stealing session cookies and performing actions on behalf of users without their consent.
No, Movable Type itself is not affected; the vulnerability is specific to the MT4i plugin.