CVE-2014-0977
Published: 10 January 2014
Cross-site scripting (XSS) vulnerability in the Rich Text Editor in Movable Type 5.0x, 5.1x before 5.161, 5.2.x before 5.2.9, and 6.0.x before 6.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Priority
Status
Package | Release | Status |
---|---|---|
movabletype-opensource Launchpad, Ubuntu, Debian |
lucid |
Ignored
(end of life)
|
precise |
Ignored
(end of life)
|
|
quantal |
Ignored
(end of life)
|
|
raring |
Ignored
(end of life)
|
|
saucy |
Ignored
(end of life)
|
|
trusty |
Does not exist
(trusty was not-affected [5.2.9+dfsg-1])
|
|
upstream |
Released
(5.2.9+dfsg-1)
|
|
utopic |
Not vulnerable
(5.2.9+dfsg-1)
|
|
vivid |
Does not exist
|
|
wily |
Does not exist
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
Patches: vendor: http://www.debian.org/security/2014/dsa-2841 |