CVE-2009-2492

Publication date 17 July 2009

Last updated 24 July 2024


Ubuntu priority

Description

Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480.

Status

Package Ubuntu Release Status
movabletype-opensource 11.04 natty
Not affected
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
9.10 karmic Ignored end of life
9.04 jaunty Ignored end of life
8.10 intrepid Ignored end of life, was needs-triage
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities