Loading
Cross-site scripting (XSS) vulnerability in Movable Type (MT) 3.33, when nofollow is disabled and unmoderated comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Comments field.
Use Six Apart vendor hub and Movable Type product page to widen CVE-2007-0231 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2009-2481, CVE-2011-2676 and CVE-2012-2644 for nearby disclosures in the same product family.