Vulnerabilities > SIX Apart > Movable Type > 3.17

DATE CVE VULNERABILITY TITLE RISK
2009-07-17 CVE-2009-2492 Cross-Site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480.
network
high complexity
six-apart six-apart-ltd sixapart CWE-79
2.6
2009-07-16 CVE-2009-2481 Improper Authentication vulnerability in multiple products
mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restrictions and (1) send e-mail to arbitrary addresses or (2) obtain sensitive information via unspecified vectors.
5.8
2005-09-28 CVE-2005-3101 Information Disclosure vulnerability in SIX Apart Movable Type 3.17
The password reset feature in Movable Type before 3.2 generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.
network
low complexity
six-apart
5.0