CMS News, Reviews and Resources

Content Management Matters ™

Home > Archives > Micro CMS
 Are you hiring? Target top talent on our CM Job Board.



Movable Type Vulnerability Found, Patched

By Brice Dunwoodie
Jan 25. 2005
Filed Under:

In an impressive display of coordinated execution, blog software maker Six Apart yesterday coordinated an emergency point release of the popular Movable Type blogging tool.

Version 3.15 fixes a vulnerability in the mail sending packages for Movable Type versions 1.0 to 3.14. The weakness allowed malicious users to send email through the application to any number of arbitrary users. Hello spammers!

Certain configuration settings were required for the exploit to manifest, but these were not uncommon. It is therefore strongly recommended that all users of Movable Type upgrade immediately.

For those users who don't want to do a full upgrade just yet, 6A have also made the fix available in the form of a plugin. You can download it as a zip (1K) or tar/gz (1K) archive.

SPONSORSHIP

CMSWire speaks to a specific audience of professionals and opinion makers focused on content management, publishing and collaboration.
Advertise here.

The plugin is compatible with all 3.x versions as well as v2.661 (and perhaps even older versions although they haven't been tested) and provides the same exact protections as the v3.15 release.

Was this article useful?

Comments

Add a Comment

Email:
Web Site:
Comments:
Security Code:
  Remember me?
  


Advertise on CMSWire





Add to Technorati Favorites