CVE-2005-4690: Low severity movable type vulnerability
Six Apart Movable Type 3.16 allows local users with blog-creation privileges to create or overwrite arbitrary files of certain types (such as HTML and image files) by selecting an arbitrary directory as a blog's top-level directory. NOTE: this issue can be used in conjunction with CVE-2005-3102 to create or overwrite arbitrary files of all types.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4690?
CVE-2005-4690 is considered a moderate severity vulnerability that allows local users to overwrite arbitrary files.
How does CVE-2005-4690 affect Movable Type?
CVE-2005-4690 affects Movable Type 3.16 by allowing users with blog-creation privileges to select any directory as the top-level directory.
Who is primarily affected by CVE-2005-4690?
Local users with blog-creation privileges on Movable Type 3.16 are primarily affected by CVE-2005-4690.
What types of files can be overwritten due to CVE-2005-4690?
CVE-2005-4690 allows the overwrite of files such as HTML and image files.
Is there a mitigation strategy for CVE-2005-4690?
To mitigate CVE-2005-4690, restrict user permissions to prevent unauthorized file creation and overwriting.