Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-5846

Опубликовано: 05 янв. 2009
Источник: nvd
CVSS2: 4
EPSS Низкий

Описание

Six Apart Movable Type (MT) before 4.23 allows remote authenticated users with create permission for posts to bypass intended access restrictions and publish posts via a "system-wide entry listing screen."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sixapart:movable_type:*:*:*:*:*:*:*:*
Версия до 4.21 (включая)
cpe:2.3:a:sixapart:movable_type:3.0d:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.1:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.01d:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.2:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.3:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.11:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.12:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.14:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.15:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.16:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.17:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.32:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.33:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.34:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:3.35:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:4.2:*:*:*:*:*:*:*

EPSS

Процентиль: 60%
0.01004
Низкий

4 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 17 лет назад

Six Apart Movable Type (MT) before 4.23 allows remote authenticated users with create permission for posts to bypass intended access restrictions and publish posts via a "system-wide entry listing screen."

debian
больше 17 лет назад

Six Apart Movable Type (MT) before 4.23 allows remote authenticated us ...

github
около 4 лет назад

Six Apart Movable Type (MT) before 4.23 allows remote authenticated users with create permission for posts to bypass intended access restrictions and publish posts via a "system-wide entry listing screen."

EPSS

Процентиль: 60%
0.01004
Низкий

4 Medium

CVSS2

Дефекты

CWE-264