First published: Thu Nov 03 2011(Updated: )
The A-Form and A-Form bamboo before 1.3.6 and 2.x before 2.0.3, and A-Form PC and PC/Mobile before 3.1, plug-ins for Movable Type do not require administrative authentication, which allows remote authenticated users to modify data via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
ark-web A-Form | <=1.3.5 | |
ark-web A-Form | =2.0.2 | |
ark-web A-Form | =1.3.5 | |
ark-web A-Form | =2.0.2 | |
ark-web A-Form | <=3.0 | |
ark-web A-Form | <=3.0 | |
Movable Type |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability CVE-2011-2676 is classified as a medium severity issue due to its ability to allow remote authenticated users to modify data without proper authentication.
To fix CVE-2011-2676, upgrade A-Form and A-Form bamboo to version 1.3.6 or higher, or A-Form PC and PC/Mobile to version 3.1 or higher.
CVE-2011-2676 affects A-Form versions up to 1.3.5, A-Form bamboo versions up to 2.0.2, and A-Form PC and PC/Mobile versions up to 3.0.
Yes, CVE-2011-2676 can be exploited remotely by authenticated users who do not require administrative authentication.
The affected software in CVE-2011-2676 is developed by Ark Web.