CVE-2008-5846
05.01.2009, 20:30
Six Apart Movable Type (MT) before 4.23 allows remote authenticated users with create permission for posts to bypass intended access restrictions and publish posts via a "system-wide entry listing screen."Enginsight
| Vendor | Product | Version |
|---|---|---|
| sixapart | movable_type | 𝑥 ≤ 4.21 |
| sixapart | movable_type | 3.0d:d |
| sixapart | movable_type | 3.1 |
| sixapart | movable_type | 3.01d:d |
| sixapart | movable_type | 3.2 |
| sixapart | movable_type | 3.3 |
| sixapart | movable_type | 3.11 |
| sixapart | movable_type | 3.12 |
| sixapart | movable_type | 3.14 |
| sixapart | movable_type | 3.15 |
| sixapart | movable_type | 3.16 |
| sixapart | movable_type | 3.17 |
| sixapart | movable_type | 3.32 |
| sixapart | movable_type | 3.33 |
| sixapart | movable_type | 3.34 |
| sixapart | movable_type | 3.35 |
| sixapart | movable_type | 4.2 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References