CVE-2012-0317
Published Mar 3, 2012
Last updated 7 years ago
Overview
- Description
- Multiple cross-site request forgery (CSRF) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to hijack the authentication of arbitrary users for requests that modify data via the (1) commenting feature or (2) community script.
- Source
- vultures@jpcert.or.jp
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-352
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sixapart:movable_type:*:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8F2D1316-CAC7-4E50-A76A-03636377785A", "versionEndIncluding": "4.37" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.28:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BAAD088A-29B4-44B4-BB90-6BEF55428902" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.29:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6DE4CBB7-14AE-45F4-9170-3C097844E8DA" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.36:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD6E7E17-E69C-43C7-A9E3-1A7339B8BF68" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.291:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "320C5974-DA38-443F-9BAF-C60E729D3148" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.292:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7020769D-803A-473A-8F1A-4984F870D6B3" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.361:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85FA0AB7-78D6-42DC-83E7-9630BD8EFCD0" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.0:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A8EF53B9-7E86-40D5-AD18-35B09BD346D0" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.01:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "46CDB676-CD09-44C4-9E49-0BC32F5EA49A" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.1:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E7179FE9-17D8-48BD-B3EC-A29D4C603A89" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.02:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "941F8723-0838-42B9-825B-C85FF01CC35A" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.04:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9733B5E7-7A7E-48D6-9F80-7AF9DFDBD76A" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.05:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A82BFEF5-275A-45E6-B42B-1FB22E278A27" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.06:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2433941D-2DC2-4155-93F7-282AD4272334" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.11:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF917586-EF61-4E4B-8739-5EDF18CCB364" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.12:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "50529598-338F-4077-ABBF-7CE00E8E7FCE" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.051:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D9C1C42D-7BC2-428F-B9CB-4BAE2D8E0E5C" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sixapart:movable_type:*:*:enterprise:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2FB744CC-02DF-46F6-A524-27DBBB3C33BF", "versionEndIncluding": "4.292" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.28:*:enterprise:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A2BA875-0C6E-4AD4-9271-CB31E2B2B072" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.29:*:enterprise:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "59DC45AB-BF7F-4817-A0FB-E3EBCA8CB761" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.291:*:enterprise:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B516CE7A-7751-4CE0-8E16-097058A6657D" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sixapart:movable_type:5.1:*:advanced:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4495F904-41A1-4915-A26D-47DA07F17D74" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.02:*:advanced:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4D930A60-15BE-43E9-9B76-D0723D9B1E23" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.04:*:advanced:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0006333C-7916-4BB3-8698-EE48D62AE67C" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.05:*:advanced:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2F400986-9A21-4C5C-95A7-F5F61D199CC7" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.06:*:advanced:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9AAB067E-EF83-4528-A0A4-06821CAEE687" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.11:*:advanced:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0A5BFC0-6F5C-48B5-BA97-9D7CA292DB8D" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.12:*:advanced:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3EAC6A53-748D-4CB8-A0BB-AE19B23D1812" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.051:*:advanced:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4E616E4E-6D78-4931-9233-3EED49B1B6AF" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sixapart:movable_type:4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8CA6D5B7-BB96-46A9-AD07-F4F744657396" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.0:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8342D067-1B16-463D-838B-D16EF7DDCCBB" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "91A91FDA-16BD-40A3-A055-1F9F61BC90A8" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.0:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A22E7F1C-19D3-4C72-8EC7-E968FDEDA780" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.0:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B8D3280-D97B-47C9-8737-8DABCA53C290" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.0:beta5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3089827B-7A32-4EA4-93EC-63B80FF5E690" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.0:beta6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A929B42C-7C65-4D62-B418-EEEF0C3D0E36" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.0:beta7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "10D3CF75-84DE-412A-BB7C-1A9889B06D16" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2CF07C91-FF25-46AC-B42A-DD6D0F72238E" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F0C879EF-5E16-49D4-9A6E-21C44C041D42" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.0:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "403A8118-6AFE-4A25-882E-1928B489C80F" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.1:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E38527C3-2E6F-4B9A-AF59-39AC2C3F7E9D" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.1:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D197DDAE-00ED-47D5-9F6A-6E15EAE56755" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.1:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C628DCF9-7F07-447F-9F1F-636D431BBD18" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "56195FCE-D933-40C6-A6A3-6AC8CFECA5DB" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.2:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0B18D123-7449-489B-B3EC-0A72B879D92D" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.2:rc4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BD8B70C3-003A-4768-B2B4-486688952BCC" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.2:rc5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "69CAACDD-2304-4F1B-AD36-5F3B06A87551" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FFB18069-B21A-4663-93B2-F055A9D7D78D" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.15:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F249491D-31C3-47D9-97B4-84C53E8C90E9" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.15:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5BBCAE47-DEB7-41F4-B21E-8E77AA76483A" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.15:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A2B6514-6F27-454A-9CF9-F198438E4B22" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E36DD87F-F918-4BDD-98B7-41527470B838" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.23:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B49D8B0-39C9-480B-9471-1846CE5A2142" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.24:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F909511A-D7B6-4033-AB99-87D6BC5741F8" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.25:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A200E33-641A-41B3-8EB3-E7380B686C8C" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.26:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52311931-CE3A-487B-B153-4066D07F63E8" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.27:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86ED3B93-8769-4A60-BAE4-C50483254905" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.28:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "703EEB4B-4747-45D5-9335-6FD5CB238F13" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.29:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36E48EE7-3212-406E-80AB-26B0206E97E3" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.35:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1ADC65FF-B4E8-4346-80DE-647BDC4A4D3C" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.36:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F8E76C88-E486-4463-BA41-6A08ECC5E214" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.37:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "93798CD5-1099-4B6A-9303-6EFD037F5B11" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.261:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4905997-E4CE-406D-BE0F-B5E2F87AA177" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.291:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45A49069-F509-4C30-BC9F-DB1FF7C39294" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.292:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E7330A56-5D69-495B-B0E9-A820B70573C5" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.361:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9951EF1D-0D13-4215-9066-C17B352E6C6F" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F978B3B9-8300-45A7-BDBD-13C504A1BCCC" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C0E810B-453A-4C22-A8AF-C8DC83104A56" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF2F85C7-77AA-4431-8017-7EE66D2216CA" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.0:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "944DAD7F-2A51-4641-AFE9-5CB6AB957923" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.0:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45E04B8D-6F13-4D7C-9D99-70718EF82BF3" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "941AF9C9-341E-4820-8B1C-5D8C5B19861A" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0AB08B1C-C527-4D51-932B-7DAC8D507F47" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.0:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "246D565F-5260-4F5E-B766-95BADF16BC59" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "59407222-BBBB-468A-8604-A50ED9F40048" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.1:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA6CA4D7-E19C-4783-88AC-8F32F2588AE6" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.1:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F8790230-BE95-496F-8212-284125FF6376" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.02:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CF488003-44FA-48F4-8F5A-46B46523E175" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.03:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B0A9628-B04F-492D-8158-DE95980CE4E4" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.04:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D910C9B1-15D1-4E8F-8901-25063D26DC3A" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F0627468-9A42-4793-8E20-F22BD433FBAF" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.06:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "995A2AAB-E9C5-4B23-8230-D04F15097909" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.07:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8ECAE19-F294-48D8-BD97-B4E01C054E3B" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AE116A08-FD4A-4BC1-A79A-513648931D4C" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8E704381-8161-4795-A7F5-9E4D8B006C92" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.031:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "98DC35B2-E679-4049-8A2B-CE2C6F7E6E89" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:5.051:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "48B948EF-0687-4C14-A8AD-9A3B5E055A1F" } ], "operator": "OR" } ] } ]