First published: Mon Jan 05 2009(Updated: )
Six Apart Movable Type (MT) before 4.23 allows remote authenticated users with create permission for posts to bypass intended access restrictions and publish posts via a "system-wide entry listing screen."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sixapart Movable Type | =3.15 | |
Sixapart Movable Type | =3.2 | |
Sixapart Movable Type | =3.32 | |
Sixapart Movable Type | =3.16 | |
Sixapart Movable Type | =3.1 | |
Sixapart Movable Type | =3.33 | |
Sixapart Movable Type | =3.14 | |
Sixapart Movable Type | =3.0d | |
Sixapart Movable Type | =3.11 | |
Sixapart Movable Type | =3.35 | |
Sixapart Movable Type | <=4.21 | |
Sixapart Movable Type | =4.2 | |
Sixapart Movable Type | =3.17 | |
Sixapart Movable Type | =3.01d | |
Sixapart Movable Type | =3.12 | |
Sixapart Movable Type | =3.3 | |
Sixapart Movable Type | =3.34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.