CVE-2013-0209
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
23/01/2013
Last modified:
11/04/2025
Description
lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sixapart:movable_type:4.21:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sixapart:movable_type:4.22:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sixapart:movable_type:4.23:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sixapart:movable_type:4.24:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sixapart:movable_type:4.25:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sixapart:movable_type:4.26:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sixapart:movable_type:4.27:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sixapart:movable_type:4.28:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sixapart:movable_type:4.28:*:enterprise:*:*:*:*:* | ||
| cpe:2.3:a:sixapart:movable_type:4.28:*:open_source:*:*:*:*:* | ||
| cpe:2.3:a:sixapart:movable_type:4.29:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sixapart:movable_type:4.29:*:enterprise:*:*:*:*:* | ||
| cpe:2.3:a:sixapart:movable_type:4.29:*:open_source:*:*:*:*:* | ||
| cpe:2.3:a:sixapart:movable_type:4.31:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sixapart:movable_type:4.32:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://openwall.com/lists/oss-security/2013/01/22/3
- http://www.movabletype.org/2013/01/movable_type_438_patch.html
- http://www.sec-1.com/blog/?p=402
- http://www.sec-1.com/blog/wp-content/uploads/2013/01/movabletype_upgrade_exec.rb_.txt
- http://openwall.com/lists/oss-security/2013/01/22/3
- http://www.movabletype.org/2013/01/movable_type_438_patch.html
- http://www.sec-1.com/blog/?p=402
- http://www.sec-1.com/blog/wp-content/uploads/2013/01/movabletype_upgrade_exec.rb_.txt



