Description
SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
References (4)
Core 4
Core References
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/61227
Third Party Advisory vendor-advisory
x_refsource_debian
https://www.debian.org/security/2015/dsa-3183
Vendor Advisory x_refsource_confirm
https://movabletype.org/news/2014/12/6.0.6.html
Vendor Advisory x_refsource_confirm
https://movabletype.org/documentation/appendices/release-notes/6.0.6.html
Scores
EPSS
0.0199
EPSS Percentile
78.5%
Details
CWE
CWE-89
Status
published
Products (18)
debian/debian_linux
7.0
sixapart/movable_type
5.2
sixapart/movable_type
5.2.2
sixapart/movable_type
5.2.3
sixapart/movable_type
5.2.4
sixapart/movable_type
5.2.5
sixapart/movable_type
5.2.6
sixapart/movable_type
5.2.7
sixapart/movable_type
5.2.8
sixapart/movable_type
5.2.9
... and 8 more
Published
Dec 16, 2014
Tracked Since
Feb 18, 2026