// For flags

CVE-2013-0209

Movable Type 4.2x/4.3x - Web Upgrade Remote Code Execution

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code.

lib/MT/Upgrade.pm en mt-upgrade.cgi en Movable Type v4.2x y v4.3x hasta v4.38 no requiere autenticación para las peticiones a las funciones de migración de base de datos, lo que permite a atacantes remotos llevar a cabo inyecciones eval y ataques de inyección SQL a través de parámetros especialmente elaborados, como se demuestra por un ataque de inyección eval contra la función core_drop_meta_for_table, dando lugar a la ejecución de código Perl.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-12-06 CVE Reserved
  • 2013-01-07 First Exploit
  • 2013-01-23 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-10-22 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.21
Search vendor "Sixapart" for product "Movable Type" and version "4.21"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.22
Search vendor "Sixapart" for product "Movable Type" and version "4.22"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.23
Search vendor "Sixapart" for product "Movable Type" and version "4.23"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.24
Search vendor "Sixapart" for product "Movable Type" and version "4.24"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.25
Search vendor "Sixapart" for product "Movable Type" and version "4.25"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.26
Search vendor "Sixapart" for product "Movable Type" and version "4.26"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.27
Search vendor "Sixapart" for product "Movable Type" and version "4.27"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.28
Search vendor "Sixapart" for product "Movable Type" and version "4.28"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.28
Search vendor "Sixapart" for product "Movable Type" and version "4.28"
enterprise
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.28
Search vendor "Sixapart" for product "Movable Type" and version "4.28"
open_source
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.29
Search vendor "Sixapart" for product "Movable Type" and version "4.29"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.29
Search vendor "Sixapart" for product "Movable Type" and version "4.29"
enterprise
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.29
Search vendor "Sixapart" for product "Movable Type" and version "4.29"
open_source
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.31
Search vendor "Sixapart" for product "Movable Type" and version "4.31"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.32
Search vendor "Sixapart" for product "Movable Type" and version "4.32"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.33
Search vendor "Sixapart" for product "Movable Type" and version "4.33"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.34
Search vendor "Sixapart" for product "Movable Type" and version "4.34"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.35
Search vendor "Sixapart" for product "Movable Type" and version "4.35"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.36
Search vendor "Sixapart" for product "Movable Type" and version "4.36"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.37
Search vendor "Sixapart" for product "Movable Type" and version "4.37"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.38
Search vendor "Sixapart" for product "Movable Type" and version "4.38"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.261
Search vendor "Sixapart" for product "Movable Type" and version "4.261"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.291
Search vendor "Sixapart" for product "Movable Type" and version "4.291"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.291
Search vendor "Sixapart" for product "Movable Type" and version "4.291"
enterprise
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.291
Search vendor "Sixapart" for product "Movable Type" and version "4.291"
open_source
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.292
Search vendor "Sixapart" for product "Movable Type" and version "4.292"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.292
Search vendor "Sixapart" for product "Movable Type" and version "4.292"
enterprise
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.292
Search vendor "Sixapart" for product "Movable Type" and version "4.292"
open_source
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.361
Search vendor "Sixapart" for product "Movable Type" and version "4.361"
-
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.36
Search vendor "Sixapart" for product "Movable Type" and version "4.36"
open_source
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.37
Search vendor "Sixapart" for product "Movable Type" and version "4.37"
open_source
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.38
Search vendor "Sixapart" for product "Movable Type" and version "4.38"
open_source
Affected
Sixapart
Search vendor "Sixapart"
Movable Type
Search vendor "Sixapart" for product "Movable Type"
4.361
Search vendor "Sixapart" for product "Movable Type" and version "4.361"
open_source
Affected