LOW
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480
Published Jul 17, 2009
2.6
LOWCVSS 2.0
EPSS 1.08%
Description
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480.
Affected products
No data.
OR
- ≤ 4.25
- 1.54
- 2.6
- 2.63
- 3.3
- 3.16
- 3.17
- 3.32
- 3.33
- 3.36
- 4
- 4
- 4
- 4
- 4.20
- 4.20
- 4.20
- 4.20
- n/a
- 3.33
- 1.00
- 1.1
- 1.2
- 1.3
- 1.4
- 1.5
- 1.31
- 3.0d
- 3.1
- 3.01d
- 3.2
- 3.3
- 3.11
- 3.12
- 3.14
- 3.15
- 3.16
- 3.17
- 3.32
- 3.33
- 3.34
- 3.35
- 4.0
- 4.0
- 4.01
- 4.1
- 4.1
- 4.01
- 4.01
- 4.01
- 4.2
- 4.2
- 4.2
- 4.12
- 4.12
- 4.21
- 4.21
- 4.21
- 4.23
- 4.23
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://jvn.jp/en/jp/JVN86472161/index.html third-party-advisoryx_refsource_JVN
- http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000042.html third-party-advisoryx_refsource_JVNDBPatch
- http://secunia.com/advisories/35534 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.securityfocus.com/bid/35885 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2009/1668 vdb-entryx_refsource_VUPENPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://jvn.jp/en/jp/JVN86472161/index.html | third-party-advisoryx_refsource_JVN | |
| http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000042.html | third-party-advisoryx_refsource_JVNDBPatch | |
| http://secunia.com/advisories/35534 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.securityfocus.com/bid/35885 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2009/1668 | vdb-entryx_refsource_VUPENPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 17, 2009
Updated Aug 7, 2024
Reserved Jul 17, 2009
Link CVE-2009-2492
CISA Vulnrichment
Updated n/a