MEDIUM · 5.5

CVE-2011-2676

The A-Form and A-Form bamboo before 1.3.6 and 2.x before 2.0.3, and A-Form PC and PC/Mobile before 3.1, plug-ins for Movable Type do not require administrative authentication, which allows remote auth...

Vulnerability Description

The A-Form and A-Form bamboo before 1.3.6 and 2.x before 2.0.3, and A-Form PC and PC/Mobile before 3.1, plug-ins for Movable Type do not require administrative authentication, which allows remote authenticated users to modify data via unspecified vectors.

CVSS Score

5.5

MEDIUM

AV:N/AC:L/Au:S/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Ark-WebA-Form<= 1.3.5
Ark-WebA-Form Bamboo1.3.5
Ark-WebA-Form Pc<= 3.0
Ark-WebA-Form Pc Mobile<= 3.0
Six ApartMovable TypeAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-2676?

CVE-2011-2676 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The A-Form and A-Form bamboo before 1.3.6 and 2.x before 2.0.3, and A-Form PC and PC/Mobile before 3.1, plug-ins for Movable Type do not require administrative authentication, which allows remote auth...

How severe is CVE-2011-2676?

CVE-2011-2676 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-2676?

Check the references section above for vendor advisories and patch information. Affected products include: Ark-Web A-Form, Ark-Web A-Form Bamboo, Ark-Web A-Form Pc, Ark-Web A-Form Pc Mobile, Six Apart Movable Type.