CVE-2013-0209
Published Jan 23, 2013
Last updated 12 years ago
Overview
- Description
- lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-287
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sixapart:movable_type:4.21:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7AD39A71-0B61-4319-BEE1-12CAD4B095A1" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E36DD87F-F918-4BDD-98B7-41527470B838" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.23:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B49D8B0-39C9-480B-9471-1846CE5A2142" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.24:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F909511A-D7B6-4033-AB99-87D6BC5741F8" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.25:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A200E33-641A-41B3-8EB3-E7380B686C8C" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.26:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52311931-CE3A-487B-B153-4066D07F63E8" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.27:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86ED3B93-8769-4A60-BAE4-C50483254905" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.28:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "703EEB4B-4747-45D5-9335-6FD5CB238F13" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.28:*:enterprise:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A2BA875-0C6E-4AD4-9271-CB31E2B2B072" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.28:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BAAD088A-29B4-44B4-BB90-6BEF55428902" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.29:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36E48EE7-3212-406E-80AB-26B0206E97E3" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.29:*:enterprise:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "59DC45AB-BF7F-4817-A0FB-E3EBCA8CB761" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.29:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6DE4CBB7-14AE-45F4-9170-3C097844E8DA" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.31:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4E3F7E4-FD59-49B2-96B8-EF8AFEB1E01A" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.32:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA5666EE-4383-417D-871F-480093A6A49D" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.33:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F273F33D-A680-4FCE-A80A-38D9BC98A7FF" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.34:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C23010F-2AEF-4574-A857-7F41F082F707" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.35:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1ADC65FF-B4E8-4346-80DE-647BDC4A4D3C" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.36:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F8E76C88-E486-4463-BA41-6A08ECC5E214" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.37:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "93798CD5-1099-4B6A-9303-6EFD037F5B11" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.38:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B053E3DC-BE9E-4AA5-90B6-362E4F4953C3" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.261:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4905997-E4CE-406D-BE0F-B5E2F87AA177" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.291:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45A49069-F509-4C30-BC9F-DB1FF7C39294" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.291:*:enterprise:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B516CE7A-7751-4CE0-8E16-097058A6657D" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.291:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "320C5974-DA38-443F-9BAF-C60E729D3148" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.292:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E7330A56-5D69-495B-B0E9-A820B70573C5" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.292:*:enterprise:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "563F69FA-34DD-4BF3-9B94-D41848E13915" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.292:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7020769D-803A-473A-8F1A-4984F870D6B3" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.361:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9951EF1D-0D13-4215-9066-C17B352E6C6F" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sixapart:movable_type:4.36:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD6E7E17-E69C-43C7-A9E3-1A7339B8BF68" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.37:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "691C9C90-E88D-4E6F-A1DD-413FC73B9EF2" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.38:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F7F06FE8-50EF-4838-B1C5-2D347AC4B4E3" }, { "criteria": "cpe:2.3:a:sixapart:movable_type:4.361:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85FA0AB7-78D6-42DC-83E7-9630BD8EFCD0" } ], "operator": "OR" } ] } ]