movabletype kayıtları
movabletype üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
27İzleyin | CVE-2012-0319İstismar yok | The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute movabletype · movable type open source · CWE-94 | Orta6,5 | — | %2,4 | 3 Mar 2012 |
24İzleyin | CVE-2021-20663İstismar yok | Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movablemovabletype · movable type · CWE-79 | Orta6,1 | — | %0,8 | 5 Mar 2021 |
24İzleyin | CVE-2021-20665İstismar yok | Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Momovabletype · movable type · CWE-79 | Orta6,1 | — | %0,8 | 5 Mar 2021 |
24İzleyin | CVE-2021-20664İstismar yok | Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Typmovabletype · movable type · CWE-79 | Orta6,1 | — | %0,8 | 5 Mar 2021 |
18İzleyin | CVE-2012-1262İstismar yok | Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, whmovabletype · movable type open source · CWE-79 | Orta4,3 | — | %1,9 | 3 Mar 2012 |
17İzleyin | CVE-2012-1497İstismar yok | The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, whimovabletype · movable type open source · CWE-22 | Orta4,0 | — | %1,8 | 3 Mar 2012 |
17İzleyin | CVE-2012-0318İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackemovabletype · movable type open source · CWE-79 | Orta4,3 | — | %1,3 | 3 Mar 2012 |
17İzleyin | CVE-2009-2480İstismar yok | Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initializedmovabletype · six apart movable type · CWE-79 | Orta4,3 | — | %1,3 | 16 Tem 2009 |
- CVE-2012-031927İzleyin
The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute
OrtaCVSS 6,5İstismar yokEPSS %2movabletype · movable type open source3 Mar 2012
- CVE-2021-2066324İzleyin
Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable
OrtaCVSS 6,1İstismar yokEPSS %1movabletype · movable type5 Mar 2021
- CVE-2021-2066524İzleyin
Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Mo
OrtaCVSS 6,1İstismar yokEPSS %1movabletype · movable type5 Mar 2021
- CVE-2021-2066424İzleyin
Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Typ
OrtaCVSS 6,1İstismar yokEPSS %1movabletype · movable type5 Mar 2021
- CVE-2012-126218İzleyin
Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, wh
OrtaCVSS 4,3İstismar yokEPSS %2movabletype · movable type open source3 Mar 2012
- CVE-2012-149717İzleyin
The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, whi
OrtaCVSS 4,0İstismar yokEPSS %2movabletype · movable type open source3 Mar 2012
- CVE-2012-031817İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attacke
OrtaCVSS 4,3İstismar yokEPSS %1movabletype · movable type open source3 Mar 2012
- CVE-2009-248017İzleyin
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initialized
OrtaCVSS 4,3İstismar yokEPSS %1movabletype · six apart movable type16 Tem 2009