| Vulnerability Name: | CVE-2003-0287 (CCN-12003) | ||||||||
| Assigned: | 2003-05-12 | ||||||||
| Published: | 2003-05-12 | ||||||||
| Updated: | 2017-07-11 | ||||||||
| Summary: | Cross-site scripting (XSS) vulnerability in Movable Type before 2.6, and possibly other versions including 2.63, allows remote attackers to insert arbitrary web script or HTML via the Name textbox, possibly when the "Allow HTML in comments?" option is enabled. | ||||||||
| CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: CCN Type: BugTraq Mailing List, Mon May 12 2003 - 13:26:59 CDT CSS found in Movable Type Source: CCN Type: BugTraq Mailing List, Mon May 12 2003 - 15:25:36 CDT Re: CSS found in Movable Type Source: CCN Type: BugTraq Mailing List, Mon May 12 2003 - 16:38:34 CDT Re: CSS found in Movable Type Source: CCN Type: BugTraq Mailing List, Tue May 13 2003 - 08:34:36 CDT Re: CSS found in Movable Type -- Nope Source: MITRE Type: CNA CVE-2003-0287 Source: BUGTRAQ Type: UNKNOWN 20030512 CSS found in Movable Type Source: BUGTRAQ Type: UNKNOWN 20030512 Re: CSS found in Movable Type Source: BUGTRAQ Type: UNKNOWN 20030513 Re: CSS found in Movable Type -- Nope Source: CCN Type: Movable Type Web site movabletype.org Source: CCN Type: OSVDB ID: 9193 Movable Type Comment Function Multiple Parameter XSS Source: BID Type: UNKNOWN 7560 Source: CCN Type: BID-7560 Movable Type Comment Form HTML Code Injection Vulnerability Source: XF Type: UNKNOWN movable-type-comment-xss(12003) Source: XF Type: UNKNOWN movable-type-comment-xss(12003) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||