Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Movable Type <= 3.33 XSS Exploit Jan 26 2007 08:52AM
teracci2002 yahoo co jp
[Description]
MT (Movable Type) is a Blog software.
MT has a XSS filter to remove scripts from user inputs,
but there are ways to evade the filter using malformed input.

[Affected]
Movable Type <= 3.33

[Exploit]
By the default, Blog readers are allowed to post comments
containing html tags.

Attac...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus