First published: Sat Dec 31 2005(Updated: )
Six Apart Movable Type 3.16 stores account names and password hashes in a cookie, which allows remote attackers to login to an account by sniffing the cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Movable Type | =3.16 | |
Movable Type | =3.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4689 has a medium severity rating due to the potential for remote attackers to gain unauthorized access to accounts.
CVE-2005-4689 allows remote attackers to log in to user accounts by sniffing cookies containing account names and password hashes.
CVE-2005-4689 specifically affects Six Apart Movable Type version 3.16.
To fix CVE-2005-4689, upgrade to a version of Movable Type that addresses this vulnerability, ideally a version later than 3.16.
Yes, CVE-2005-4689 can potentially lead to data breaches as it enables attackers to access user accounts if they can intercept the cookie.