First published: Sat Dec 31 2005(Updated: )
Six Apart Movable Type 3.16 allows local users with blog-creation privileges to create or overwrite arbitrary files of certain types (such as HTML and image files) by selecting an arbitrary directory as a blog's top-level directory. NOTE: this issue can be used in conjunction with CVE-2005-3102 to create or overwrite arbitrary files of all types.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Movable Type | =3.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4690 is considered a moderate severity vulnerability that allows local users to overwrite arbitrary files.
CVE-2005-4690 affects Movable Type 3.16 by allowing users with blog-creation privileges to select any directory as the top-level directory.
Local users with blog-creation privileges on Movable Type 3.16 are primarily affected by CVE-2005-4690.
CVE-2005-4690 allows the overwrite of files such as HTML and image files.
To mitigate CVE-2005-4690, restrict user permissions to prevent unauthorized file creation and overwriting.