Loading
Cross-site scripting (XSS) vulnerability in the Rich Text Editor in Movable Type 5.0x, 5.1x before 5.161, 5.2.x before 5.2.9, and 6.0.x before 6.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Use CWE-79, Sixapart vendor hub and Movabletype product page to widen CVE-2014-0977 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2010-4511, CVE-2010-4509 and CVE-2015-0845 for nearby disclosures in the same product family.