Unrated severityNVD Advisory· Published Nov 3, 2011· Updated Apr 29, 2026
CVE-2011-3993
CVE-2011-3993
Description
SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Movable Type, uses weak permissions, which allows remote authenticated users to modify files and settings via unspecified vectors.
Affected products
17cpe:2.3:a:skyarc:mtcms:*:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:skyarc:mtcms:*:*:*:*:*:*:*:*range: <=5.251
- cpe:2.3:a:skyarc:mtcms:5.2:*:*:*:*:*:*:*
- cpe:2.3:a:skyarc:mtcms:5.21:*:*:*:*:*:*:*
- cpe:2.3:a:skyarc:mtcms:5.22:*:*:*:*:*:*:*
- cpe:2.3:a:skyarc:mtcms:5.23:*:*:*:*:*:*:*
- cpe:2.3:a:skyarc:mtcms:5.24:*:*:*:*:*:*:*
- cpe:2.3:a:skyarc:mtcms:5.24:*:enterprise:*:*:*:*:*
- cpe:2.3:a:skyarc:mtcms:5.24:*:smart:*:*:*:*:*
- cpe:2.3:a:skyarc:mtcms:5.25:*:*:*:*:*:*:*
- cpe:2.3:a:skyarc:mtcms:5.25:*:enterprise:*:*:*:*:*
- cpe:2.3:a:skyarc:mtcms:5.25:*:smart:*:*:*:*:*
- cpe:2.3:a:skyarc:mtcms:5.251:*:enterprise:*:*:*:*:*
- cpe:2.3:a:skyarc:mtcms:5.251:*:smart:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.