CVE-2011-2676

ark-web a-form < 1.3.6 and 2.x < 2.0.3 - Improper Authentication

Title source: llm
STIX 2.1

Description

The A-Form and A-Form bamboo before 1.3.6 and 2.x before 2.0.3, and A-Form PC and PC/Mobile before 3.1, plug-ins for Movable Type do not require administrative authentication, which allows remote authenticated users to modify data via unspecified vectors.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/70408
Third Party Advisory third-party-advisory x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2011-000078
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN34980730/index.html

Scores

EPSS 0.0126
EPSS Percentile 66.0%

Details

CWE
CWE-287
Status published
Products (6)
ark-web/a-form 2.0.2
ark-web/a-form < 1.3.5
ark-web/a-form_bamboo 1.3.5
ark-web/a-form_bamboo 2.0.2
ark-web/a-form_pc < 3.0
ark-web/a-form_pc_mobile < 3.0
Published Nov 03, 2011
Tracked Since Feb 18, 2026