CVE-2013-0209 Information
Feb 14, 2021
cve
Description
lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters as demonstrated by an eval injection attack against the core_drop_meta_for_table function leading to execution of arbitrary Perl code.
Reference
http://openwall.com/lists/oss-security/2013/01/22/3 http://www.movabletype.org/2013/01/movable_type_438_patch.html http://www.sec-1.com/blog/?p=402 http://www.sec-1.com/blog/wp-content/uploads/2013/01/movabletype_upgrade_exec.rb_.txt
Share on: