Search Results (24 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2005-3104 1 Six Apart 1 Movable Type 2025-04-03 N/A
mt-comments.cgi in Movable Type before 3.2 allows attackers to redirect users to other web sites via URLs in comments.
CVE-2005-3103 1 Six Apart 1 Movable Type 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in Movable Type before 3.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title, (2) category, (3) body, (4) extended body, and (5) excerpt form fields in new blog entries.
CVE-2005-3102 1 Six Apart 1 Movable Type 2025-04-03 N/A
The administrative interface in Movable Type allows attackers to upload files with arbitrary extensions under the web root.
CVE-2005-4689 1 Six Apart 1 Movable Type 2025-04-03 N/A
Six Apart Movable Type 3.16 stores account names and password hashes in a cookie, which allows remote attackers to login to an account by sniffing the cookie.