Movable Type Remote File Include Vulnerability
BID:14910
Info
Movable Type Remote File Include Vulnerability
| Bugtraq ID: | 14910 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2005 12:00AM |
| Updated: | Sep 22 2005 12:00AM |
| Credit: | Tim Brown is credited with the discovery of this vulnerability. |
| Vulnerable: |
Movable Type Movable Type 3.17 |
| Not Vulnerable: |
Movable Type Movable Type 3.2 |
Discussion
Movable Type Remote File Include Vulnerability
Movable Type is prone to a remote file include vulnerability. This is due to a lack of proper sanitization of user-supplied input.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Movable Type is prone to a remote file include vulnerability. This is due to a lack of proper sanitization of user-supplied input.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Exploit / POC
Movable Type Remote File Include Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Movable Type Remote File Include Vulnerability
Solution:
The vendor has released version 3.2 to address this issue.
Movable Type Movable Type 3.17
Solution:
The vendor has released version 3.2 to address this issue.
Movable Type Movable Type 3.17
-
Movable Type MT-3.2-en_US.tar.gz
http://www.sixapart.com/movabletype/
References
Movable Type Remote File Include Vulnerability
References:
References:
- Movable Type Change Log (Movable Type)
- Movable Type Homepage (Movable Type)