CVE-2012-0317

Multiple cross-site request forgery (CSRF) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to hijack the authentication of arbitrary users for requests that modify data via the (1) commenting feature or (2) community script.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
jpcertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
sixapartmovable_type
𝑥
≤ 4.37
sixapartmovable_type
4.28
sixapartmovable_type
4.29
sixapartmovable_type
4.36
sixapartmovable_type
4.291
sixapartmovable_type
4.292
sixapartmovable_type
4.361
sixapartmovable_type
5.0
sixapartmovable_type
5.01
sixapartmovable_type
5.1
sixapartmovable_type
5.02
sixapartmovable_type
5.04
sixapartmovable_type
5.05
sixapartmovable_type
5.06
sixapartmovable_type
5.11
sixapartmovable_type
5.12
sixapartmovable_type
5.051
sixapartmovable_type
𝑥
≤ 4.292
sixapartmovable_type
4.28
sixapartmovable_type
4.29
sixapartmovable_type
4.291
sixapartmovable_type
5.1
sixapartmovable_type
5.02
sixapartmovable_type
5.04
sixapartmovable_type
5.05
sixapartmovable_type
5.06
sixapartmovable_type
5.11
sixapartmovable_type
5.12
sixapartmovable_type
5.051
sixapartmovable_type
4.0
sixapartmovable_type
4.0:beta
sixapartmovable_type
4.0:beta2
sixapartmovable_type
4.0:beta3
sixapartmovable_type
4.0:beta4
sixapartmovable_type
4.0:beta5
sixapartmovable_type
4.0:beta6
sixapartmovable_type
4.0:beta7
sixapartmovable_type
4.0:rc1
sixapartmovable_type
4.0:rc2
sixapartmovable_type
4.0:rc3
sixapartmovable_type
4.1:beta
sixapartmovable_type
4.1:beta2
sixapartmovable_type
4.1:rc1
sixapartmovable_type
4.2
sixapartmovable_type
4.2:rc2
sixapartmovable_type
4.2:rc4
sixapartmovable_type
4.2:rc5
sixapartmovable_type
4.12
sixapartmovable_type
4.15:beta1
sixapartmovable_type
4.15:beta3
sixapartmovable_type
4.15:beta4
sixapartmovable_type
4.22
sixapartmovable_type
4.23
sixapartmovable_type
4.24
sixapartmovable_type
4.25
sixapartmovable_type
4.26
sixapartmovable_type
4.27
sixapartmovable_type
4.28
sixapartmovable_type
4.29
sixapartmovable_type
4.35
sixapartmovable_type
4.36
sixapartmovable_type
4.37
sixapartmovable_type
4.261
sixapartmovable_type
4.291
sixapartmovable_type
4.292
sixapartmovable_type
4.361
sixapartmovable_type
5.0
sixapartmovable_type
5.0:beta1
sixapartmovable_type
5.0:beta2
sixapartmovable_type
5.0:beta3
sixapartmovable_type
5.0:beta4
sixapartmovable_type
5.0:rc1
sixapartmovable_type
5.0:rc2
sixapartmovable_type
5.0:rc3
sixapartmovable_type
5.01
sixapartmovable_type
5.1:beta
sixapartmovable_type
5.1:rc1
sixapartmovable_type
5.02
sixapartmovable_type
5.03
sixapartmovable_type
5.04
sixapartmovable_type
5.05
sixapartmovable_type
5.06
sixapartmovable_type
5.07
sixapartmovable_type
5.11
sixapartmovable_type
5.12
sixapartmovable_type
5.031
sixapartmovable_type
5.051
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
movabletype-opensource
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
not-affected
trusty
dne
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
ignored
oneiric
ignored
natty
ignored
maverick
ignored
lucid
ignored
hardy
dne