Six Apart Movable Type 3.16 stores account names and password hashes in a cookie, which allows remote attackers to login to an account by sniffing the cookie.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Movable_type |
Six_apart |
3.16 (including) |
3.16 (including) |
References