PT-2011-4020 · Six Apart · Movable Type+1
Publicado
2011-11-03
·
Atualizado
2017-08-29
·
CVE-2011-2676
CVSS v2.0
5.5
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
A-Form and A-Form bamboo versions prior to 1.3.6
A-Form and A-Form bamboo versions 2.x prior to 2.0.3
A-Form PC and PC/Mobile versions prior to 3.1
Description
The issue allows remote authenticated users to modify data without requiring administrative authentication. This is due to a lack of authentication requirement in plug-ins for Movable Type, which can be exploited via unspecified vectors.
Recommendations
For A-Form and A-Form bamboo versions prior to 1.3.6, update to version 1.3.6 or later.
For A-Form and A-Form bamboo versions 2.x prior to 2.0.3, update to version 2.0.3 or later.
For A-Form PC and PC/Mobile versions prior to 3.1, update to version 3.1 or later.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
A-Form
Movable Type