{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-14T21:18:58.986","vulnerabilities":[{"cve":{"id":"CVE-2010-3921","sourceIdentifier":"vultures@jpcert.or.jp","published":"2010-12-09T20:00:17.570","lastModified":"2026-04-29T01:13:23.040","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."},{"lang":"es","value":"Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Movable Type v4.x anterior v4.35 y v5.x anterior v5.04 permite a atacantes remotos ejecutar comandos SQL de su elección a través de vectores no especificados."}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:4.0:*:*:*:*:*:*:*","matchCriteriaId":"8FC86B27-E526-481B-9840-8CC2765FCA44"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:4.1:*:*:*:*:*:*:*","matchCriteriaId":"EE55B1A6-5088-4308-A324-995A697CFA5E"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:4.2:*:*:*:*:*:*:*","matchCriteriaId":"A414C73F-C8E3-424E-8A59-932A767F5FB4"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:4.3:*:*:*:*:*:*:*","matchCriteriaId":"735BEFA2-07E3-4040-9E61-0DA4A5563AC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:4.23:*:*:*:*:*:*:*","matchCriteriaId":"02A2E180-EE8E-4F1F-8942-1AE52A7136CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:4.25:*:*:*:*:*:*:*","matchCriteriaId":"9CBFF9B6-8600-4E64-A47D-FF470EDA2BAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:4.26:*:*:*:*:*:*:*","matchCriteriaId":"66E75D18-2099-40E9-8DE8-A596716DA474"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:4.31:*:*:*:*:*:*:*","matchCriteriaId":"E8210508-9185-4AF3-AF60-DBB006B82C08"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:4.32:*:*:*:*:*:*:*","matchCriteriaId":"02871C60-E082-465B-A907-8583FB1223B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:4.33:*:*:*:*:*:*:*","matchCriteriaId":"BEA2FA53-7C32-4A73-A161-C64D21603F45"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:4.34:*:*:*:*:*:*:*","matchCriteriaId":"8B35AB3E-C117-43C1-AA02-6EA6A50FDE3A"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:4.261:*:*:*:*:*:*:*","matchCriteriaId":"1DC10F85-874F-4317-BE3C-F8F0FFF3176A"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:5.0:rc2:*:*:*:*:*:*","matchCriteriaId":"77E0EB61-EE1A-4FA3-A644-81F0A551987D"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:5.01:*:*:*:*:*:*:*","matchCriteriaId":"12468D6E-01F2-4AE4-9E6A-F096FB12DF2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:5.02:*:*:*:*:*:*:*","matchCriteriaId":"9C783A30-16F4-42B1-A180-0E6E9988C365"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:5.03:*:*:*:*:*:*:*","matchCriteriaId":"ACB4D3BC-5B51-4F04-8991-4CFADBCD52DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movabletype:5.031:*:*:*:*:*:*:*","matchCriteriaId":"30E2D15B-83EB-47B8-9D41-B49C6430463A"}]}]}],"references":[{"url":"http://jvn.jp/en/jp/JVN36673836/index.html","source":"vultures@jpcert.or.jp"},{"url":"http://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000060.html","source":"vultures@jpcert.or.jp"},{"url":"http://secunia.com/advisories/42539","source":"vultures@jpcert.or.jp","tags":["Vendor Advisory"]},{"url":"http://www.movabletype.org/documentation/appendices/release-notes/movable-type-504-435-release-notes.html","source":"vultures@jpcert.or.jp"},{"url":"http://www.securitytracker.com/id?1024833","source":"vultures@jpcert.or.jp"},{"url":"http://www.vupen.com/english/advisories/2010/3145","source":"vultures@jpcert.or.jp"},{"url":"http://jvn.jp/en/jp/JVN36673836/index.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000060.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://secunia.com/advisories/42539","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://www.movabletype.org/documentation/appendices/release-notes/movable-type-504-435-release-notes.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id?1024833","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.vupen.com/english/advisories/2010/3145","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}