mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restrictions and (1) send e-mail to arbitrary addresses or (2) obtain sensitive information via unspecified vectors.
2009-07-16T16:30:00.420
2025-04-09T00:30:58.490
Deferred
CVSSv2: 5.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | six_apart | movable_type | 1.54 | Yes |
Application | six_apart | movable_type | 2.6 | Yes |
Application | six_apart | movable_type | 2.63 | Yes |
Application | six_apart | movable_type | 3.3 | Yes |
Application | six_apart | movable_type | 3.16 | Yes |
Application | six_apart | movable_type | 3.17 | Yes |
Application | six_apart | movable_type | 3.32 | Yes |
Application | six_apart | movable_type | 3.33 | Yes |
Application | six_apart | movable_type | 3.36 | Yes |
Application | six_apart | movable_type | 4.20 | Yes |
Application | six_apart | movable_type | 4.20 | Yes |
Application | six_apart | movable_type | 4.20 | Yes |
Application | six_apart | movable_type | 4.20 | Yes |
Application | six_apart | movable_type | 4.25 | Yes |
Application | sixapart | movable_type | ≤ 4.26 | Yes |
Application | sixapart | movable_type | 1.00 | Yes |
Application | sixapart | movable_type | 1.1 | Yes |
Application | sixapart | movable_type | 1.2 | Yes |
Application | sixapart | movable_type | 1.3 | Yes |
Application | sixapart | movable_type | 1.4 | Yes |
Application | sixapart | movable_type | 1.5 | Yes |
Application | sixapart | movable_type | 1.31 | Yes |
Application | sixapart | movable_type | 3.0d | Yes |
Application | sixapart | movable_type | 3.1 | Yes |
Application | sixapart | movable_type | 3.01d | Yes |
Application | sixapart | movable_type | 3.2 | Yes |
Application | sixapart | movable_type | 3.3 | Yes |
Application | sixapart | movable_type | 3.11 | Yes |
Application | sixapart | movable_type | 3.12 | Yes |
Application | sixapart | movable_type | 3.14 | Yes |
Application | sixapart | movable_type | 3.15 | Yes |
Application | sixapart | movable_type | 3.16 | Yes |
Application | sixapart | movable_type | 3.17 | Yes |
Application | sixapart | movable_type | 3.32 | Yes |
Application | sixapart | movable_type | 3.33 | Yes |
Application | sixapart | movable_type | 3.34 | Yes |
Application | sixapart | movable_type | 3.35 | Yes |
Application | sixapart | movable_type | 4.0 | Yes |
Application | sixapart | movable_type | 4.0 | Yes |
Application | sixapart | movable_type | 4.01 | Yes |
Application | sixapart | movable_type | 4.1 | Yes |
Application | sixapart | movable_type | 4.1 | Yes |
Application | sixapart | movable_type | 4.01 | Yes |
Application | sixapart | movable_type | 4.01 | Yes |
Application | sixapart | movable_type | 4.01 | Yes |
Application | sixapart | movable_type | 4.2 | Yes |
Application | sixapart | movable_type | 4.2 | Yes |
Application | sixapart | movable_type | 4.2 | Yes |
Application | sixapart | movable_type | 4.12 | Yes |
Application | sixapart | movable_type | 4.12 | Yes |
Application | sixapart | movable_type | 4.21 | Yes |
Application | sixapart | movable_type | 4.21 | Yes |
Application | sixapart | movable_type | 4.21 | Yes |
Application | sixapart | movable_type | 4.23 | Yes |
Application | sixapart | movable_type | 4.23 | Yes |
Application | sixapart | movable_type | 4.23 | Yes |
Application | sixapart | movable_type | 4.25 | Yes |