Movable Type Arbitrary Blog Creation Path Vulnerability

Movable Type is prone to a vulnerability that allows attackers to create files outside of the Movable Type directory path. This issue occurs because the application fails to properly sanitize user-supplied input.

Note that this vulnerability can occur only when a validated user has sufficient permissions to create blog entries.


 

Privacy Statement
Copyright 2010, SecurityFocus