Release date:
Updated on:
Affected Systems:
Movable Type 4.37
Movable Type 4.361
Movable Type 4.36
Movable Type 4.35
Movable Type 4.34
Movable Type 4.27
Movable Type 4.261
Movable Type 4.26
Movable Type 4.25
Movable Type 4.24
Movable Type 4.23
Movable Type 4.22
Movable Type 4.21
Unaffected system:
Movable Type 4.38
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57490
CVE (CAN) ID: CVE-2013-0209
Movable Type is a multi-functional social publishing platform.
Previous versions of Movable Type 4.38 have multiple SQL injection and Command Injection Vulnerabilities. Successful exploitation of these vulnerabilities allows attackers to execute unauthorized database operations or arbitrary code.
<* Source: vendor
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Movable Type
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.movabletype.org/