7.5
CVSSv2

CVE-2014-9057

Published: 16/12/2014 Updated: 17/11/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the XML-RPC interface in Movable Type prior to 5.18, 5.2.x prior to 5.2.11, and 6.x prior to 6.0.6 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 7.0

sixapart movable type 6.0.5

sixapart movable type 6.0

sixapart movable type 5.2.2

sixapart movable type 5.2.4

sixapart movable type 5.2.9

sixapart movable type

sixapart movable type 6.0.4

sixapart movable type 6.0.3

sixapart movable type 6.0.2

sixapart movable type 6.0.1

sixapart movable type 5.2.5

sixapart movable type 5.2.6

sixapart movable type 5.2.7

sixapart movable type 5.2.8

sixapart movable type 5.2

sixapart movable type 5.2.3

sixapart movable type 5.2.10

Vendor Advisories

Multiple vulnerabilities have been discovered in Movable Type, a blogging system The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-2184 Unsafe use of Storable::thaw in the handling of comments to blog posts could allow remote attackers to include and execute arbitrary local Perl files or poss ...