| Vulnerability Name: | CVE-2005-3102 (CCN-22369) | ||||||||
| Assigned: | 2005-09-22 | ||||||||
| Published: | 2005-09-22 | ||||||||
| Updated: | 2008-09-05 | ||||||||
| Summary: | The administrative interface in Movable Type allows attackers to upload files with arbitrary extensions under the web root. | ||||||||
| CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: FULLDISC Type: UNKNOWN 20051103 Buggy blogging Source: MITRE Type: CNA CVE-2005-3102 Source: MITRE Type: CNA CVE-2005-4690 Source: CCN Type: SA16899 Movable Type Multiple Weaknesses and Vulnerabilities Source: SECUNIA Type: Vendor Advisory 16899 Source: CCN Type: OSVDB ID: 19602 Movable Type File Upload Extension Validation Weakness Source: CCN Type: OSVDB ID: 24110 Movable Type Top-level Directory Manipulation Weakness Source: CCN Type: BID-14910 Movable Type Remote File Include Vulnerability Source: CCN Type: BID-15302 Movable Type Arbitrary Blog Creation Path Vulnerability Source: CCN Type: Movable Type Web site Movable Type Source: XF Type: UNKNOWN moveabletype-file-upload(22369) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||