Unrated severityNVD Advisory· Published Jul 17, 2009· Updated Apr 23, 2026
CVE-2009-2492
CVE-2009-2492
Description
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480.
Affected products
60cpe:2.3:a:six_apart_ltd:movable_type:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:six_apart_ltd:movable_type:*:*:*:*:*:*:*:*
- cpe:2.3:a:six_apart_ltd:movable_type:3.33:*:*:*:*:*:*:*
cpe:2.3:a:six_apart:movable_type:*:*:*:*:*:*:*:*+ 57 more
- cpe:2.3:a:six_apart:movable_type:*:*:*:*:*:*:*:*range: <=4.25
- cpe:2.3:a:sixapart:movable_type:1.00:*:enterprise:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:1.1:*:enterprise:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:1.2:*:enterprise:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:1.31:*:enterprise:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:1.3:*:enterprise:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:1.4:*:enterprise:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:1.54:*:enterprise:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:1.5:*:enterprise:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:2.6:*:*:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:2.63:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:3.01d:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:3.0d:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:3.1:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:3.11:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:3.12:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:3.14:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:3.15:*:*:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:3.16:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:3.16:*:*:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:3.17:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:3.17:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:3.2:*:*:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:3.3:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:3.3:*:*:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:3.32:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:3.32:*:*:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:3.33:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:3.33:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:3.34:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:3.35:*:*:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:3.36:*:enterprise:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:4:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.01:b:community_solution:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.01:b:pro:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.01:-:community_solution:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.01:-:pro:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.0:-:community_solution:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.0:-:pro:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.12:-:community_solution:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.12:-:pro:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.1:-:community_solution:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.1:-:pro:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.2:*:*:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:4.20:*:*:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:4.20:*:community_solution:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:4.20:*:enterprise:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:4.20:*:open_source:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.21:*:*:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.21:-:community_solution:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.21:-:pro:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.23:-:community_solution:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.23:-:pro:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.2:-:community_solution:*:*:*:*:*
- cpe:2.3:a:sixapart:movable_type:4.2:-:pro:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:4:*:community_solution:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:4:*:enterprise:*:*:*:*:*
- cpe:2.3:a:six_apart:movable_type:4:*:open_source:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000042.htmlnvdPatch
- www.vupen.com/english/advisories/2009/1668nvdPatchVendor Advisory
- secunia.com/advisories/35534nvdVendor Advisory
- jvn.jp/en/jp/JVN86472161/index.htmlnvd
- www.securityfocus.com/bid/35885nvd
News mentions
0No linked articles in our index yet.