CVE-2009-2481

mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restrictions and (1) send e-mail to arbitrary addresses or (2) obtain sensitive information via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
VendorProductVersion
six_apartmovable_type
1.54
six_apartmovable_type
2.6
six_apartmovable_type
2.63
six_apartmovable_type
3.3
six_apartmovable_type
3.16
six_apartmovable_type
3.17
six_apartmovable_type
3.32
six_apartmovable_type
3.33
six_apartmovable_type
3.36
six_apartmovable_type
4.20
six_apartmovable_type
4.20
six_apartmovable_type
4.20
six_apartmovable_type
4.20
six_apartmovable_type
4.25
sixapartmovable_type
𝑥
≤ 4.26
sixapartmovable_type
1.00
sixapartmovable_type
1.1
sixapartmovable_type
1.2
sixapartmovable_type
1.3
sixapartmovable_type
1.4
sixapartmovable_type
1.5
sixapartmovable_type
1.31
sixapartmovable_type
3.0d:d
sixapartmovable_type
3.1
sixapartmovable_type
3.01d:d
sixapartmovable_type
3.2
sixapartmovable_type
3.3
sixapartmovable_type
3.11
sixapartmovable_type
3.12
sixapartmovable_type
3.14
sixapartmovable_type
3.15
sixapartmovable_type
3.16
sixapartmovable_type
3.17
sixapartmovable_type
3.32
sixapartmovable_type
3.33
sixapartmovable_type
3.34
sixapartmovable_type
3.35
sixapartmovable_type
4.0
sixapartmovable_type
4.0
sixapartmovable_type
4.01
sixapartmovable_type
4.1
sixapartmovable_type
4.1
sixapartmovable_type
4.01
sixapartmovable_type
4.01:b
sixapartmovable_type
4.01:b
sixapartmovable_type
4.2
sixapartmovable_type
4.2
sixapartmovable_type
4.2
sixapartmovable_type
4.12
sixapartmovable_type
4.12
sixapartmovable_type
4.21
sixapartmovable_type
4.21
sixapartmovable_type
4.21
sixapartmovable_type
4.23
sixapartmovable_type
4.23
sixapartmovable_type
4.23
sixapartmovable_type
4.25
𝑥
= Vulnerable software versions