7.5
CVSSv2

CVE-2013-2184

Published: 27/03/2015 Updated: 27/03/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Movable Type prior to 5.2.6 does not properly use the Storable::thaw function, which allows remote malicious users to execute arbitrary code via the comment_state parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sixapart movable type

Vendor Advisories

Multiple vulnerabilities have been discovered in Movable Type, a blogging system The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-2184 Unsafe use of Storable::thaw in the handling of comments to blog posts could allow remote attackers to include and execute arbitrary local Perl files or poss ...