CVE-2009-2481

Six Apart Movable Type <4.261 - Auth Bypass

Title source: llm

Description

mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restrictions and (1) send e-mail to arbitrary addresses or (2) obtain sensitive information via unspecified vectors.

Scores

EPSS 0.0035
EPSS Percentile 57.1%

Classification

CWE
CWE-287
Status draft

Affected Products (50)

six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
six_apart/movable_type
sixapart/movable_type < 4.26
... and 35 more

Timeline

Published Jul 16, 2009
Tracked Since Feb 18, 2026