CVE-2011-2676
ark-web a-form < 1.3.6 and 2.x < 2.0.3 - Improper Authentication
Title source: llmDescription
The A-Form and A-Form bamboo before 1.3.6 and 2.x before 2.0.3, and A-Form PC and PC/Mobile before 3.1, plug-ins for Movable Type do not require administrative authentication, which allows remote authenticated users to modify data via unspecified vectors.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/70408
Patch x_refsource_confirm
http://www.ark-web.jp/movabletype/a-form/docs/security_patch.html
Third Party Advisory third-party-advisory
x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2011-000078
Patch x_refsource_confirm
http://www.ark-web.jp/movabletype/blog/2011/09/aform_update110927.html
Third Party Advisory third-party-advisory
x_refsource_jvn
http://jvn.jp/en/jp/JVN34980730/index.html
Scores
EPSS
0.0126
EPSS Percentile
66.0%
Details
CWE
CWE-287
Status
published
Products (6)
ark-web/a-form
2.0.2
ark-web/a-form
< 1.3.5
ark-web/a-form_bamboo
1.3.5
ark-web/a-form_bamboo
2.0.2
ark-web/a-form_pc
< 3.0
ark-web/a-form_pc_mobile
< 3.0
Published
Nov 03, 2011
Tracked Since
Feb 18, 2026