CVE-2009-2492
Six Apart Movable Type <4.261 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480.
References (5)
Scores
EPSS
0.0036
EPSS Percentile
57.6%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
six_apart/movable_type
< 4.25
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
... and 35 more
Timeline
Published
Jul 17, 2009
Tracked Since
Feb 18, 2026