CVE-2011-2676: Medium severity ark-web a-form vulnerability
The A-Form and A-Form bamboo before 1.3.6 and 2.x before 2.0.3, and A-Form PC and PC/Mobile before 3.1, plug-ins for Movable Type do not require administrative authentication, which allows remote authenticated users to modify data via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2676?
The vulnerability CVE-2011-2676 is classified as a medium severity issue due to its ability to allow remote authenticated users to modify data without proper authentication.
How do I fix CVE-2011-2676?
To fix CVE-2011-2676, upgrade A-Form and A-Form bamboo to version 1.3.6 or higher, or A-Form PC and PC/Mobile to version 3.1 or higher.
What software versions are affected by CVE-2011-2676?
CVE-2011-2676 affects A-Form versions up to 1.3.5, A-Form bamboo versions up to 2.0.2, and A-Form PC and PC/Mobile versions up to 3.0.
Can CVE-2011-2676 be exploited remotely?
Yes, CVE-2011-2676 can be exploited remotely by authenticated users who do not require administrative authentication.
Who is the vendor for the affected software in CVE-2011-2676?
The affected software in CVE-2011-2676 is developed by Ark Web.