Movable Type Username Information Disclosure Vulnerability
BID:14911
Info
Movable Type Username Information Disclosure Vulnerability
| Bugtraq ID: | 14911 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2005 12:00AM |
| Updated: | Sep 22 2005 12:00AM |
| Credit: | Tim Brown is credited with the discovery of this vulnerability. |
| Vulnerable: |
Movable Type Movable Type 3.17 |
| Not Vulnerable: |
Movable Type Movable Type 3.2 |
Discussion
Movable Type Username Information Disclosure Vulnerability
Movable Type is prone to an information disclosure vulnerability. The application will respond with different messages with regards to the validity of an entered username.
This allows for attackers to obtain a list of valid application users, which could aid in brute force attacks.
Movable Type is prone to an information disclosure vulnerability. The application will respond with different messages with regards to the validity of an entered username.
This allows for attackers to obtain a list of valid application users, which could aid in brute force attacks.
Exploit / POC
Movable Type Username Information Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Movable Type Username Information Disclosure Vulnerability
Solution:
The vendor has released version 3.2 to address this issue.
Movable Type Movable Type 3.17
Solution:
The vendor has released version 3.2 to address this issue.
Movable Type Movable Type 3.17
-
Movable Type MT-3.2-en_US.tar.gz
http://www.sixapart.com/movabletype/
References
Movable Type Username Information Disclosure Vulnerability
References:
References:
- Movable Type Change Log (Movable Type)
- Movable Type Homepage (Movable Type)