MovableType Spam Exploit
The patch for this came out several days ago, but I'm running into a lot of people who haven't upgraded their MovableType install and they really, really need to. There's a flaw in the script handling comment notification, and all installs below 3.15 are vulnerable if they have it turned on, allowing evildoers to send emails out to any arbitrary person they choose. Namely, spam. Upgrade.
It's become somewhat de jour to treat security flaws as happy accident to promote upgrading in their user base, but SixApart also made the patch available as a plugin for those who haven't upgraded to 3.x. They should be commended for it, it was cool of them to do.

Posted by drunkenbatman





