Another MT Mail Exploit.
The MovableType Comment/Trackback/… system (which uses email to notify the blog owner of newly posted comments/trackbacks) is vulnerable to being exploited by spammers. (Surprised?)
Update now, before the spammers get around to your blog.
Posted by distler at January 25, 2005 2:20 AM
Re: Another MT Mail Exploit.
While I did remember the existence of the
mt-send-entry.cgi
problem, I’d rather forgotten the details until I reread your entry and saw that first proposed patch.So, shall we assume that now everything has been looked at carefully, and everything goes through the patched is_valid_email, or shall we look ourselves?