Show plain JSON{"id": "CVE-2013-0209", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2013-01-23T01:55:01.150", "references": [{"url": "http://openwall.com/lists/oss-security/2013/01/22/3", "source": "secalert@redhat.com"}, {"url": "http://www.movabletype.org/2013/01/movable_type_438_patch.html", "tags": ["Patch", "Vendor Advisory"], "source": "secalert@redhat.com"}, {"url": "http://www.sec-1.com/blog/?p=402", "tags": ["Exploit"], "source": "secalert@redhat.com"}, {"url": "http://www.sec-1.com/blog/wp-content/uploads/2013/01/movabletype_upgrade_exec.rb_.txt", "tags": ["Exploit"], "source": "secalert@redhat.com"}, {"url": "http://openwall.com/lists/oss-security/2013/01/22/3", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.movabletype.org/2013/01/movable_type_438_patch.html", "tags": ["Patch", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.sec-1.com/blog/?p=402", "tags": ["Exploit"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.sec-1.com/blog/wp-content/uploads/2013/01/movabletype_upgrade_exec.rb_.txt", "tags": ["Exploit"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-287"}]}], "descriptions": [{"lang": "en", "value": "lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code."}, {"lang": "es", "value": "lib/MT/Upgrade.pm en mt-upgrade.cgi en Movable Type v4.2x y v4.3x hasta v4.38 no requiere autenticaci\u00f3n para las peticiones a las funciones de migraci\u00f3n de base de datos, lo que permite a atacantes remotos llevar a cabo inyecciones eval y ataques de inyecci\u00f3n SQL a trav\u00e9s de par\u00e1metros especialmente elaborados, como se demuestra por un ataque de inyecci\u00f3n eval contra la funci\u00f3n core_drop_meta_for_table, dando lugar a la ejecuci\u00f3n de c\u00f3digo Perl."}], "lastModified": "2025-04-11T00:51:21.963", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:sixapart:movable_type:4.21:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7AD39A71-0B61-4319-BEE1-12CAD4B095A1"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E36DD87F-F918-4BDD-98B7-41527470B838"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.23:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B49D8B0-39C9-480B-9471-1846CE5A2142"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.24:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F909511A-D7B6-4033-AB99-87D6BC5741F8"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.25:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A200E33-641A-41B3-8EB3-E7380B686C8C"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.26:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52311931-CE3A-487B-B153-4066D07F63E8"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.27:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86ED3B93-8769-4A60-BAE4-C50483254905"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.28:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "703EEB4B-4747-45D5-9335-6FD5CB238F13"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.28:*:enterprise:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A2BA875-0C6E-4AD4-9271-CB31E2B2B072"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.28:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BAAD088A-29B4-44B4-BB90-6BEF55428902"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.29:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36E48EE7-3212-406E-80AB-26B0206E97E3"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.29:*:enterprise:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "59DC45AB-BF7F-4817-A0FB-E3EBCA8CB761"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.29:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6DE4CBB7-14AE-45F4-9170-3C097844E8DA"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.31:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4E3F7E4-FD59-49B2-96B8-EF8AFEB1E01A"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.32:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA5666EE-4383-417D-871F-480093A6A49D"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.33:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F273F33D-A680-4FCE-A80A-38D9BC98A7FF"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.34:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C23010F-2AEF-4574-A857-7F41F082F707"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.35:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1ADC65FF-B4E8-4346-80DE-647BDC4A4D3C"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.36:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F8E76C88-E486-4463-BA41-6A08ECC5E214"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.37:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "93798CD5-1099-4B6A-9303-6EFD037F5B11"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.38:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B053E3DC-BE9E-4AA5-90B6-362E4F4953C3"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.261:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4905997-E4CE-406D-BE0F-B5E2F87AA177"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.291:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45A49069-F509-4C30-BC9F-DB1FF7C39294"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.291:*:enterprise:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B516CE7A-7751-4CE0-8E16-097058A6657D"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.291:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "320C5974-DA38-443F-9BAF-C60E729D3148"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.292:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E7330A56-5D69-495B-B0E9-A820B70573C5"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.292:*:enterprise:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "563F69FA-34DD-4BF3-9B94-D41848E13915"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.292:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7020769D-803A-473A-8F1A-4984F870D6B3"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.361:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9951EF1D-0D13-4215-9066-C17B352E6C6F"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:sixapart:movable_type:4.36:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD6E7E17-E69C-43C7-A9E3-1A7339B8BF68"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.37:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "691C9C90-E88D-4E6F-A1DD-413FC73B9EF2"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.38:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F7F06FE8-50EF-4838-B1C5-2D347AC4B4E3"}, {"criteria": "cpe:2.3:a:sixapart:movable_type:4.361:*:open_source:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85FA0AB7-78D6-42DC-83E7-9630BD8EFCD0"}], "operator": "OR"}]}], "sourceIdentifier": "secalert@redhat.com"}