CVE-2009-2481
Six Apart Movable Type <4.261 - Auth Bypass
Title source: llmDescription
mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restrictions and (1) send e-mail to arbitrary addresses or (2) obtain sensitive information via unspecified vectors.
References (6)
Scores
EPSS
0.0035
EPSS Percentile
57.1%
Classification
CWE
CWE-287
Status
draft
Affected Products (50)
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
sixapart/movable_type
< 4.26
... and 35 more
Timeline
Published
Jul 16, 2009
Tracked Since
Feb 18, 2026