CVE-2013-0209

lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
sixapartmovable_type
4.21
sixapartmovable_type
4.22
sixapartmovable_type
4.23
sixapartmovable_type
4.24
sixapartmovable_type
4.25
sixapartmovable_type
4.26
sixapartmovable_type
4.27
sixapartmovable_type
4.28
sixapartmovable_type
4.28
sixapartmovable_type
4.28
sixapartmovable_type
4.29
sixapartmovable_type
4.29
sixapartmovable_type
4.29
sixapartmovable_type
4.31
sixapartmovable_type
4.32
sixapartmovable_type
4.33
sixapartmovable_type
4.34
sixapartmovable_type
4.35
sixapartmovable_type
4.36
sixapartmovable_type
4.37
sixapartmovable_type
4.38
sixapartmovable_type
4.261
sixapartmovable_type
4.291
sixapartmovable_type
4.291
sixapartmovable_type
4.291
sixapartmovable_type
4.292
sixapartmovable_type
4.292
sixapartmovable_type
4.292
sixapartmovable_type
4.361
sixapartmovable_type
4.36
sixapartmovable_type
4.37
sixapartmovable_type
4.38
sixapartmovable_type
4.361
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
movabletype-opensource
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
not-affected
trusty
dne
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
ignored
oneiric
ignored
lucid
ignored
hardy
dne