← Back

CVE-2008-5846

nvd nist
Published: Jan 5, 2009Modified: Apr 23, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:L/Au:S/C:N/I:P/A:N
Exploitability: 8.0 / Impact: 2.9
Source: NVD

Description

Six Apart Movable Type (MT) before 4.23 allows remote authenticated users with create permission for posts to bypass intended access restrictions and publish posts via a "system-wide entry listing screen."

Affected (17)

1 product
Movable Type
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Sixapart
Up to 4.21
Version 3.01d
Version 3.0d
Version 3.11
Version 3.12
Version 3.14
Version 3.15
Version 3.16
Version 3.17
Version 3.1
Version 3.2
Version 3.32
Version 3.33
Version 3.34
Version 3.35
Version 3.3
Version 4.2

Related CWEs

References (6)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.