CVE-2014-9057

Movable Type <5.18, <5.2.11, <6.0.6 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

References (4)

Core 4
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61227
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2015/dsa-3183
Vendor Advisory x_refsource_confirm
https://movabletype.org/news/2014/12/6.0.6.html

Scores

EPSS 0.0199
EPSS Percentile 78.5%

Details

CWE
CWE-89
Status published
Products (18)
debian/debian_linux 7.0
sixapart/movable_type 5.2
sixapart/movable_type 5.2.2
sixapart/movable_type 5.2.3
sixapart/movable_type 5.2.4
sixapart/movable_type 5.2.5
sixapart/movable_type 5.2.6
sixapart/movable_type 5.2.7
sixapart/movable_type 5.2.8
sixapart/movable_type 5.2.9
... and 8 more
Published Dec 16, 2014
Tracked Since Feb 18, 2026