CVE-2011-2676

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
03/11/2011
Last modified:
11/04/2025

Description

The A-Form and A-Form bamboo before 1.3.6 and 2.x before 2.0.3, and A-Form PC and PC/Mobile before 3.1, plug-ins for Movable Type do not require administrative authentication, which allows remote authenticated users to modify data via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ark-web:a-form:*:*:*:*:*:*:*:* 1.3.5 (including)
cpe:2.3:a:ark-web:a-form:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ark-web:a-form_bamboo:1.3.5:*:*:*:*:*:*:*
cpe:2.3:a:ark-web:a-form_bamboo:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ark-web:a-form_pc:*:*:*:*:*:*:*:* 3.0 (including)
cpe:2.3:a:ark-web:a-form_pc_mobile:*:*:*:*:*:*:*:* 3.0 (including)
cpe:2.3:a:six_apart:movable_type:*:*:*:*:*:*:*:*