← Back

CVE-2013-0209

nvd nist
Published: Jan 23, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code.

Affected (33)

1 product
Movable Type
Configuration A
29 vulnerable
Vulnerable SoftwareAffected Versions
Sixapart
Version 4.21
Version 4.22
Version 4.23
Version 4.24
Version 4.25
Version 4.261
Version 4.26
Version 4.27
Version 4.28
Version 4.28
Version 4.28
Version 4.291
Version 4.291
Version 4.291
Version 4.292
Version 4.292
Version 4.292
Version 4.29
Version 4.29
Version 4.29
Version 4.31
Version 4.32
Version 4.33
Version 4.34
Version 4.35
Version 4.361
Version 4.36
Version 4.37
Version 4.38
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Sixapart
Version 4.361
Version 4.36
Version 4.37
Version 4.38

References (8)

Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.