Vulnerabilities > SIX Apart > Movable Type > 3.17
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-07-17 | CVE-2009-2492 | Cross-Site Scripting vulnerability in multiple products Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480. | 2.6 |
2009-07-16 | CVE-2009-2481 | Improper Authentication vulnerability in multiple products mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restrictions and (1) send e-mail to arbitrary addresses or (2) obtain sensitive information via unspecified vectors. | 5.8 |
2005-09-28 | CVE-2005-3101 | Information Disclosure vulnerability in SIX Apart Movable Type 3.17 The password reset feature in Movable Type before 3.2 generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames. | 5.0 |