CVE-2008-5846

Six Apart Movable Type (MT) before 4.23 allows remote authenticated users with create permission for posts to bypass intended access restrictions and publish posts via a "system-wide entry listing screen."
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sixapart:movable_type:*:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.0d:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.1:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.01d:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.2:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.3:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.11:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.12:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.14:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.15:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.16:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.17:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.32:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.33:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.34:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.35:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.2:*:*:*:*:*:*:*

History

21 Nov 2024, 00:55

Type Values Removed Values Added
References () http://www.movabletype.org/mt_423_change_log.html - () http://www.movabletype.org/mt_423_change_log.html -
References () http://www.securityfocus.com/bid/33133 - () http://www.securityfocus.com/bid/33133 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/47759 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/47759 -

Information

Published : 2009-01-05 20:30

Updated : 2024-11-21 00:55


NVD link : CVE-2008-5846

Mitre link : CVE-2008-5846

CVE.ORG link : CVE-2008-5846


JSON object : View

Products Affected

sixapart

  • movable_type
CWE
CWE-264

Permissions, Privileges, and Access Controls