Wordpress Themes - Creative Electronics - Find jobs - ID card - Rome hotels

PDA

View Full Version : Movable Type - vulnerability - update recommended


expat
Jan 27th 2005, 9:02 am
Unusually although not using it I got a warning from a couple of my ISP's / hosts

Anyone using should update if not already done so

........................................Late last night the makers of Movable Type announced that avulnerability existed in all versions of Movable Type.Movable Type is a software that is not supplied by xxxxxx, however it is very popular with our client base. If you are not using Movable Type, please ignore this email.This exploit in all versions of Movable Type allowed a malicioususer to exploit the e-mail functions of Movable Type and send unlimited spam e-mail from the targeted site.
....................................

Epat

Movable Type 3.15 released
01.24.2005
Version 3.15 fixes a vulnerability in the mail sending packages for all Movable Type versions in which the user has enabled comment notifications. This vulnerability allows a malicious user to send email through the application to any number of arbitrary users.

All Movable Type users should install this update.

nevetS
Jan 27th 2005, 5:06 pm
There's a notice in your mt.cgi page when you go in to admin your site.

expat
Jan 28th 2005, 1:27 am
OK, good to know, I try not to regurgitate these warnings but on some of my hosts exploits where already been traced, which obviously led to shut down of sites.

Expat