First published: Fri Jul 17 2009(Updated: )
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Movable Type | =3.36 | |
Six Apart Movable Type | =3.15 | |
Six Apart Movable Type | =3.2 | |
Six Apart Movable Type | =4.0 | |
Six Apart Movable Type | =3.32 | |
Six Apart Movable Type | =3.16 | |
Six Apart Movable Type | =1.5 | |
Six Apart Movable Type | =3.1 | |
Six Apart Movable Type | =1.00 | |
Six Apart Movable Type | =3.33 | |
Six Apart Movable Type | =4.23 | |
Movable Type | =4 | |
Six Apart Movable Type | =3.14 | |
Six Apart Movable Type | =3.0d | |
Six Apart Movable Type | =4.01-b | |
Six Apart Movable Type | =4.0 | |
Movable Type | =4.20 | |
Movable Type | =4 | |
Six Apart Movable Type | =4.23 | |
Movable Type | =3.17 | |
Six Apart Movable Type | =1.4 | |
Six Apart Movable Type | =3.11 | |
Six Apart Movable Type | =3.35 | |
Six Apart Movable Type | =1.1 | |
Six Apart Movable Type | =4.2 | |
Six Apart Movable Type | =1.3 | |
Movable Type | =4.20 | |
Six Apart Movable Type | =4.1 | |
Movable Type | =3.3 | |
Movable Type | =2.63 | |
Six Apart Movable Type | ||
Six Apart Movable Type | =4.01 | |
Six Apart Movable Type | =4.01 | |
Six Apart Movable Type | =4.21 | |
Six Apart Movable Type | =4.2 | |
Six Apart Movable Type | =4.2 | |
Movable Type | =3.33 | |
Movable Type | =1.54 | |
Movable Type | =4 | |
Movable Type | =3.16 | |
Movable Type | =2.6 | |
Six Apart Movable Type | =3.17 | |
Six Apart Movable Type | =1.2 | |
Six Apart Movable Type | =3.01d | |
Six Apart Movable Type | =1.31 | |
Six Apart Movable Type | =4.01-b | |
Six Apart Movable Type | =4.12 | |
Movable Type | =4.20 | |
Movable Type | =3.32 | |
Movable Type | <=4.25 | |
Six Apart Movable Type | =3.12 | |
Six Apart Movable Type | =3.3 | |
Movable Type | =4 | |
Movable Type | =4.20 | |
Six Apart Movable Type | =3.34 | |
Six Apart Movable Type | =4.1 | |
Six Apart Movable Type | =4.21 | |
Six Apart Movable Type | =3.33 | |
Six Apart Movable Type | =4.12 | |
Six Apart Movable Type | =4.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2492 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2009-2492, upgrade your Movable Type installation to version 4.261 or later.
CVE-2009-2492 affects Movable Type versions 1.0 through 4.260.
Yes, CVE-2009-2492 can potentially allow attackers to steal sensitive user data through malicious scripts.
In the context of CVE-2009-2492, cross-site scripting (XSS) allows attackers to inject malicious scripts into web pages viewed by users.