Vulnerabilities > SIX Apart > Movable Type > 3.3

DATE CVE VULNERABILITY TITLE RISK
2009-07-17 CVE-2009-2492 Cross-Site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480.
network
high complexity
six-apart six-apart-ltd sixapart CWE-79
2.6
2009-07-16 CVE-2009-2481 Improper Authentication vulnerability in multiple products
mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restrictions and (1) send e-mail to arbitrary addresses or (2) obtain sensitive information via unspecified vectors.
5.8
2006-09-29 CVE-2006-5080 Cross-Site Scripting vulnerability in SIX Apart Movable Type
Cross-site scripting (XSS) vulnerability in the search function in Six Apart Movable Type 3.3 to 3.32, and Movable Type Enterprise 1.01 and 1.02, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
six-apart CWE-79
4.3