Vulnerabilities > SIX Apart > Movable Type > 4
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-07-17 | CVE-2009-2492 | Cross-Site Scripting vulnerability in multiple products Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480. | 2.6 |
2009-01-02 | CVE-2008-5808 | Cross-Site Scripting vulnerability in multiple products Cross-site scripting (XSS) vulnerability in Six Apart Movable Type Enterprise (MTE) 1.x before 1.56; Movable Type (MT) 3.x before 3.38; and Movable Type, Movable Type Open Source (MTOS), and Movable Type Enterprise 4.x before 4.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to "application management." | 4.3 |
2008-10-21 | CVE-2008-4634 | Cross-Site Scripting vulnerability in SIX Apart Movable Type 4/4.20 Cross-site scripting (XSS) vulnerability in Movable Type 4 through 4.21 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the administrative page, a different vulnerability than CVE-2008-4079. | 3.5 |
2008-09-15 | CVE-2008-4079 | Cross-Site Scripting vulnerability in SIX Apart Movable Type Cross-site scripting (XSS) vulnerability in Movable Type (MT) 4.x through 4.20, and 3.36 and earlier; Movable Type Enterprise 4.x through 4.20, and 1.54 and earlier; and Movable Type Community Solution allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 4.3 |