CVE-2009-2481

mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restrictions and (1) send e-mail to arbitrary addresses or (2) obtain sensitive information via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:six_apart:movable_type:1.54:*:enterprise:*:*:*:*:*
cpe:2.3:a:six_apart:movable_type:2.6:*:*:*:*:*:*:*
cpe:2.3:a:six_apart:movable_type:2.63:*:*:*:*:*:*:*
cpe:2.3:a:six_apart:movable_type:3.3:*:*:*:*:*:*:*
cpe:2.3:a:six_apart:movable_type:3.16:*:*:*:*:*:*:*
cpe:2.3:a:six_apart:movable_type:3.17:*:*:*:*:*:*:*
cpe:2.3:a:six_apart:movable_type:3.32:*:*:*:*:*:*:*
cpe:2.3:a:six_apart:movable_type:3.33:*:*:*:*:*:*:*
cpe:2.3:a:six_apart:movable_type:3.36:*:enterprise:*:*:*:*:*
cpe:2.3:a:six_apart:movable_type:4.20:*:*:*:*:*:*:*
cpe:2.3:a:six_apart:movable_type:4.20:*:community_solution:*:*:*:*:*
cpe:2.3:a:six_apart:movable_type:4.20:*:enterprise:*:*:*:*:*
cpe:2.3:a:six_apart:movable_type:4.20:*:open_source:*:*:*:*:*
cpe:2.3:a:six_apart:movable_type:4.25:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:*:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:1.00:*:enterprise:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:1.1:*:enterprise:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:1.2:*:enterprise:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:1.3:*:enterprise:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:1.4:*:enterprise:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:1.5:*:enterprise:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:1.31:*:enterprise:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.0d:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.1:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.01d:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.2:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.3:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.11:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.12:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.14:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.15:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.16:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.17:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.32:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.33:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.34:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.35:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.0:-:community_solution:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.0:-:pro:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.01:-:community_solution:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.1:-:community_solution:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.1:-:pro:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.01:-:pro:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.01:b:community_solution:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.01:b:pro:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.2:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.2:-:community_solution:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.2:-:pro:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.12:-:community_solution:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.12:-:pro:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.21:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.21:-:community_solution:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.21:-:pro:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.23:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.23:-:community_solution:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.23:-:pro:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.25:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-07-16 16:30

Updated : 2023-12-10 10:51


NVD link : CVE-2009-2481

Mitre link : CVE-2009-2481

CVE.ORG link : CVE-2009-2481


JSON object : View

Products Affected

six_apart

  • movable_type

sixapart

  • movable_type
CWE
CWE-287

Improper Authentication

NVD-CWE-noinfo