Description
SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open Source 5.2.13 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
References (5)
Core 5
Core References
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/06/22/5
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1036160
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/06/22/3
Release Notes, Vendor Advisory x_refsource_confirm
https://movabletype.org/news/2016/06/movable_type_626_and_613_released.html
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/06/22/6
Scores
CVSS v3
9.8
EPSS
0.0164
EPSS Percentile
74.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (16)
sixapart/movable_type
6.0 (2 CPE variants)
sixapart/movable_type
6.0.1 (2 CPE variants)
sixapart/movable_type
6.0.2 (2 CPE variants)
sixapart/movable_type
6.0.3 (2 CPE variants)
sixapart/movable_type
6.0.4 (2 CPE variants)
sixapart/movable_type
6.0.5 (2 CPE variants)
sixapart/movable_type
6.0.6 (2 CPE variants)
sixapart/movable_type
6.0.7 (2 CPE variants)
sixapart/movable_type
6.0.8 (2 CPE variants)
sixapart/movable_type
6.1.0 (2 CPE variants)
... and 6 more
Published
Jan 23, 2017
Tracked Since
Feb 18, 2026