Записи movabletype
8 опубликованных записей вендора movabletype.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
27Наблюдать | CVE-2012-0319Эксплойта нет | The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute movabletype · movable type open source · CWE-94 | Средняя6,5 | — | 2,4 % | 3 мар. 2012 г. |
24Наблюдать | CVE-2021-20663Эксплойта нет | Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movablemovabletype · movable type · CWE-79 | Средняя6,1 | — | 0,8 % | 5 мар. 2021 г. |
24Наблюдать | CVE-2021-20665Эксплойта нет | Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Momovabletype · movable type · CWE-79 | Средняя6,1 | — | 0,8 % | 5 мар. 2021 г. |
24Наблюдать | CVE-2021-20664Эксплойта нет | Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Typmovabletype · movable type · CWE-79 | Средняя6,1 | — | 0,8 % | 5 мар. 2021 г. |
18Наблюдать | CVE-2012-1262Эксплойта нет | Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, whmovabletype · movable type open source · CWE-79 | Средняя4,3 | — | 1,9 % | 3 мар. 2012 г. |
17Наблюдать | CVE-2012-1497Эксплойта нет | The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, whimovabletype · movable type open source · CWE-22 | Средняя4,0 | — | 1,8 % | 3 мар. 2012 г. |
17Наблюдать | CVE-2012-0318Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackemovabletype · movable type open source · CWE-79 | Средняя4,3 | — | 1,3 % | 3 мар. 2012 г. |
17Наблюдать | CVE-2009-2480Эксплойта нет | Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initializedmovabletype · six apart movable type · CWE-79 | Средняя4,3 | — | 1,3 % | 16 июл. 2009 г. |
- CVE-2012-031927Наблюдать
The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute
СредняяCVSS 6,5Эксплойта нетEPSS 2 %movabletype · movable type open source3 мар. 2012 г.
- CVE-2021-2066324Наблюдать
Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable
СредняяCVSS 6,1Эксплойта нетEPSS 1 %movabletype · movable type5 мар. 2021 г.
- CVE-2021-2066524Наблюдать
Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Mo
СредняяCVSS 6,1Эксплойта нетEPSS 1 %movabletype · movable type5 мар. 2021 г.
- CVE-2021-2066424Наблюдать
Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Typ
СредняяCVSS 6,1Эксплойта нетEPSS 1 %movabletype · movable type5 мар. 2021 г.
- CVE-2012-126218Наблюдать
Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, wh
СредняяCVSS 4,3Эксплойта нетEPSS 2 %movabletype · movable type open source3 мар. 2012 г.
- CVE-2012-149717Наблюдать
The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, whi
СредняяCVSS 4,0Эксплойта нетEPSS 2 %movabletype · movable type open source3 мар. 2012 г.
- CVE-2012-031817Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attacke
СредняяCVSS 4,3Эксплойта нетEPSS 1 %movabletype · movable type open source3 мар. 2012 г.
- CVE-2009-248017Наблюдать
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initialized
СредняяCVSS 4,3Эксплойта нетEPSS 1 %movabletype · six apart movable type16 июл. 2009 г.