CVE-2009-2480
Six Apart Movable Type <4.25 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initialized, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References (7)
Scores
EPSS
0.0052
EPSS Percentile
66.3%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
movabletype/six_apart_movable_type
movabletype/six_apart_movable_type
n/a/n/a
Timeline
Published
Jul 16, 2009
Tracked Since
Feb 18, 2026