On June the 22nd Six Apart KK announced movable type v5.12, v5.06 and v4.37 as mandatory security updates mentioning that these updates resolve multiple vulnerabilities discovered in Movable Type 5.x and Movable Type 4.x and that all users must upgrade to this latest release immediately.
The impact of the vulnerabilities is described as:
Under certain circumstances, a user who has "Create Entries" or "Manage Blog" pemissions may be able to read known files on the local file system.
Go ahead and upgrade your installation right away or hire me to upgrade it on your behalf.




