← Back

CVE-2008-5845

nvd nist
Published: Jan 5, 2009Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in Six Apart Movable Type (MT) before 4.23 allow remote attackers to inject arbitrary web script or HTML via a (1) MTEntryAuthorUsername, (2) MTAuthorDisplayName, (3) MTEntryAuthorDisplayName, or (4) MTCommenterName field in a Profile View template; a (5) listing screen or (6) edit screen in the CMS app; (7) a TrackBack title, related to the HTML sanitization library; or (8) a user archive name (aka archive title) on a published Community Blog template.

Affected (17)

1 product
Movable Type
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Sixapart
Up to 4.21
Version 3.01d
Version 3.0d
Version 3.11
Version 3.12
Version 3.14
Version 3.15
Version 3.16
Version 3.17
Version 3.1
Version 3.2
Version 3.32
Version 3.33
Version 3.34
Version 3.35
Version 3.3
Version 4.2

References (6)

Timeline

No history available yet.