CVE-2008-5808

Six Apart MTE <1.56-4.23 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Six Apart Movable Type Enterprise (MTE) 1.x before 1.56; Movable Type (MT) 3.x before 3.38; and Movable Type, Movable Type Open Source (MTOS), and Movable Type Enterprise 4.x before 4.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to "application management."

Scores

EPSS 0.0047
EPSS Percentile 64.5%

Classification

CWE
CWE-79
Status published

Affected Products (29)

six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
sixapart/movable_type
sixapart/movable_type
sixapart/movable_type
sixapart/movable_type
sixapart/movable_type
sixapart/movable_type
sixapart/movable_type
sixapart/movable_type
sixapart/movable_type
... and 14 more

Timeline

Published Jan 02, 2009
Tracked Since Feb 18, 2026