CVE-2009-2480: XSS
Published Jul 16, 2009
·Updated
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initialized, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
2 affected components
Movabletype Six Apart Movable Type=4.24
Movabletype Six Apart Movable Type=4.25
Event History
Jul 16, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2480?
CVE-2009-2480 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2009-2480?
To fix CVE-2009-2480, users should upgrade to Movable Type versions 4.26 or later where this vulnerability is addressed.
3
What components are affected by CVE-2009-2480?
CVE-2009-2480 specifically affects the mt-wizard.cgi component of Six Apart Movable Type versions 4.24 and 4.25.
4
What type of vulnerability is CVE-2009-2480?
CVE-2009-2480 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2009-2480 be exploited remotely?
Yes, CVE-2009-2480 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.