← Back

CVE-2011-3994

nvd nist
Published: Nov 3, 2011Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Cross-site request forgery (CSRF) vulnerability in SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Movable Type, allows remote attackers to hijack the authentication of arbitrary users for requests that modify data.

Affected (17)

5 products
Autotagging
Duplicateentry
Mailpack
Mtcms
Multifileuploader
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.08
Up to 1.2
Up to 1.741
Skyarc
Up to 5.251
Version 5.21
Version 5.22
Version 5.23
Version 5.24
Version 5.24
Version 5.24
Version 5.251
Version 5.251
Version 5.25
Version 5.25
Version 5.25
Version 5.2
Up to 0.44

References (6)

Source: vultures@jpcert.or.jp
Source: vultures@jpcert.or.jp
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.