CVE-2009-2492

Six Apart Movable Type <4.261 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480.

Scores

EPSS 0.0036
EPSS Percentile 57.6%

Classification

CWE
CWE-79
Status published

Affected Products (50)

six_apart/movable_type < 4.25
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
... and 35 more

Timeline

Published Jul 17, 2009
Tracked Since Feb 18, 2026