CVE-2005-4689: Medium severity Six Apart Movable Type vulnerability
Six Apart Movable Type 3.16 stores account names and password hashes in a cookie, which allows remote attackers to login to an account by sniffing the cookie.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4689?
CVE-2005-4689 has a medium severity rating due to the potential for remote attackers to gain unauthorized access to accounts.
How does CVE-2005-4689 affect user accounts?
CVE-2005-4689 allows remote attackers to log in to user accounts by sniffing cookies containing account names and password hashes.
What versions of Movable Type are affected by CVE-2005-4689?
CVE-2005-4689 specifically affects Six Apart Movable Type version 3.16.
How do I fix CVE-2005-4689?
To fix CVE-2005-4689, upgrade to a version of Movable Type that addresses this vulnerability, ideally a version later than 3.16.
Can CVE-2005-4689 result in data breaches?
Yes, CVE-2005-4689 can potentially lead to data breaches as it enables attackers to access user accounts if they can intercept the cookie.