First published: Thu Jul 16 2009(Updated: )
mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restrictions and (1) send e-mail to arbitrary addresses or (2) obtain sensitive information via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Movable Type | =1.54 | |
Movable Type | =2.6 | |
Movable Type | =2.63 | |
Movable Type | =3.3 | |
Movable Type | =3.16 | |
Movable Type | =3.17 | |
Movable Type | =3.32 | |
Movable Type | =3.33 | |
Movable Type | =3.36 | |
Movable Type | =4.20 | |
Movable Type | =4.20 | |
Movable Type | =4.20 | |
Movable Type | =4.20 | |
Movable Type | =4.25 | |
Six Apart Movable Type | <=4.26 | |
Six Apart Movable Type | =1.00 | |
Six Apart Movable Type | =1.1 | |
Six Apart Movable Type | =1.2 | |
Six Apart Movable Type | =1.3 | |
Six Apart Movable Type | =1.4 | |
Six Apart Movable Type | =1.5 | |
Six Apart Movable Type | =1.31 | |
Six Apart Movable Type | =3.0d | |
Six Apart Movable Type | =3.1 | |
Six Apart Movable Type | =3.01d | |
Six Apart Movable Type | =3.2 | |
Six Apart Movable Type | =3.3 | |
Six Apart Movable Type | =3.11 | |
Six Apart Movable Type | =3.12 | |
Six Apart Movable Type | =3.14 | |
Six Apart Movable Type | =3.15 | |
Six Apart Movable Type | =3.16 | |
Six Apart Movable Type | =3.17 | |
Six Apart Movable Type | =3.32 | |
Six Apart Movable Type | =3.33 | |
Six Apart Movable Type | =3.34 | |
Six Apart Movable Type | =3.35 | |
Six Apart Movable Type | =4.0 | |
Six Apart Movable Type | =4.0 | |
Six Apart Movable Type | =4.01 | |
Six Apart Movable Type | =4.1 | |
Six Apart Movable Type | =4.1 | |
Six Apart Movable Type | =4.01 | |
Six Apart Movable Type | =4.01-b | |
Six Apart Movable Type | =4.01-b | |
Six Apart Movable Type | =4.2 | |
Six Apart Movable Type | =4.2 | |
Six Apart Movable Type | =4.2 | |
Six Apart Movable Type | =4.12 | |
Six Apart Movable Type | =4.12 | |
Six Apart Movable Type | =4.21 | |
Six Apart Movable Type | =4.21 | |
Six Apart Movable Type | =4.21 | |
Six Apart Movable Type | =4.23 | |
Six Apart Movable Type | =4.23 | |
Six Apart Movable Type | =4.23 | |
Six Apart Movable Type | =4.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2481 has been classified with a moderate severity level due to its ability to bypass access restrictions.
To resolve CVE-2009-2481, upgrade to Movable Type version 4.261 or later.
CVE-2009-2481 affects multiple versions of Movable Type up to 4.260, including versions 1.0 to 4.260.
Attackers exploiting CVE-2009-2481 can send emails to arbitrary addresses or obtain sensitive information.
Yes, CVE-2009-2481 allows remote attackers to exploit the vulnerability without any local access.