The administrative interface in Movable Type allows attackers to upload files with arbitrary extensions under the web root.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-3102
http://secunia.com/advisories/16899
http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0091.html