Six Apart Movable Type 3.16 stores account names and password hashes in a cookie, which allows remote attackers to login to an account by sniffing the cookie.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0091.html | mailing list vendor advisory |
http://www.sixapart.com/movabletype/docs/3.2/h_changelog/3_2.html |