Vulnerabilities > Movabletype > Movable Type Open Source > 5.03

DATE CVE VULNERABILITY TITLE RISK
2012-03-03 CVE-2012-1497 Path Traversal vulnerability in Movabletype products
The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files by leveraging the template-designer role.
network
low complexity
movabletype CWE-22
4.0
2012-03-03 CVE-2012-1262 Cross-Site Scripting vulnerability in Movabletype products
Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the dbuser parameter, a different vulnerability than CVE-2012-0318.
4.3
2012-03-03 CVE-2012-0319 Code Injection vulnerability in Movabletype products
The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute arbitrary commands by leveraging the file-upload feature, related to an "OS Command Injection" issue.
network
low complexity
movabletype CWE-94
6.5
2012-03-03 CVE-2012-0318 Cross-Site Scripting vulnerability in Movabletype products
Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to inject arbitrary web script or HTML via vectors involving templates, a different issue than CVE-2012-1262.
4.3