Movable Type Multiple SQL Injection and Command Injection Vulnerabilities
BID:57490
Info
Movable Type Multiple SQL Injection and Command Injection Vulnerabilities
| Bugtraq ID: | 57490 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-6315 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2013 12:00AM |
| Updated: | Mar 19 2015 09:28AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Movable Type Movable Type 4.37 Movable Type Movable Type 4.361 Movable Type Movable Type 4.36 Movable Type Movable Type 4.35 Movable Type Movable Type 4.34 Movable Type Movable Type 4.27 Movable Type Movable Type 4.261 Movable Type Movable Type 4.26 Movable Type Movable Type 4.25 Movable Type Movable Type 4.24 Movable Type Movable Type 4.23 Movable Type Movable Type 4.22 Movable Type Movable Type 4.21 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Movable Type Movable Type 4.38 |
Discussion
Movable Type Multiple SQL Injection and Command Injection Vulnerabilities
Movable Type is prone to multiple SQL-injection and command-injection vulnerabilities because the application fails to properly sanitize user-supplied input.
Exploiting these issues could allow an attacker to execute arbitrary code, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Movable Type 4.38 are vulnerable.
Movable Type is prone to multiple SQL-injection and command-injection vulnerabilities because the application fails to properly sanitize user-supplied input.
Exploiting these issues could allow an attacker to execute arbitrary code, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Movable Type 4.38 are vulnerable.
Exploit / POC
Movable Type Multiple SQL Injection and Command Injection Vulnerabilities
Attackers can exploit these issues using a browser or readily available tools.
The following exploit code is available:
Attackers can exploit these issues using a browser or readily available tools.
The following exploit code is available:
Solution / Fix
Movable Type Multiple SQL Injection and Command Injection Vulnerabilities
Solution:
Updates are available. Please see the references for more details.
Movable Type Movable Type 4.25
Movable Type Movable Type 4.34
Movable Type Movable Type 4.21
Movable Type Movable Type 4.27
Movable Type Movable Type 4.261
Movable Type Movable Type 4.24
Movable Type Movable Type 4.26
Movable Type Movable Type 4.22
Movable Type Movable Type 4.37
Movable Type Movable Type 4.35
Movable Type Movable Type 4.361
Movable Type Movable Type 4.36
Movable Type Movable Type 4.23
Solution:
Updates are available. Please see the references for more details.
Movable Type Movable Type 4.25
-
Movable Type MT-4.38-Upgrade-Patch.zip
http://www.movabletype.org/downloads/patches/MT-4.38-Upgrade-Patch.zip
Movable Type Movable Type 4.34
-
Movable Type MT-4.38-Upgrade-Patch.zip
http://www.movabletype.org/downloads/patches/MT-4.38-Upgrade-Patch.zip
Movable Type Movable Type 4.21
-
Movable Type MT-4.38-Upgrade-Patch.zip
http://www.movabletype.org/downloads/patches/MT-4.38-Upgrade-Patch.zip
Movable Type Movable Type 4.27
-
Movable Type MT-4.38-Upgrade-Patch.zip
http://www.movabletype.org/downloads/patches/MT-4.38-Upgrade-Patch.zip
Movable Type Movable Type 4.261
-
Movable Type MT-4.38-Upgrade-Patch.zip
http://www.movabletype.org/downloads/patches/MT-4.38-Upgrade-Patch.zip
Movable Type Movable Type 4.24
-
Movable Type MT-4.38-Upgrade-Patch.zip
http://www.movabletype.org/downloads/patches/MT-4.38-Upgrade-Patch.zip
Movable Type Movable Type 4.26
-
Movable Type MT-4.38-Upgrade-Patch.zip
http://www.movabletype.org/downloads/patches/MT-4.38-Upgrade-Patch.zip
Movable Type Movable Type 4.22
-
Movable Type MT-4.38-Upgrade-Patch.zip
http://www.movabletype.org/downloads/patches/MT-4.38-Upgrade-Patch.zip
Movable Type Movable Type 4.37
-
Movable Type MT-4.38-Upgrade-Patch.zip
http://www.movabletype.org/downloads/patches/MT-4.38-Upgrade-Patch.zip
Movable Type Movable Type 4.35
-
Movable Type MT-4.38-Upgrade-Patch.zip
http://www.movabletype.org/downloads/patches/MT-4.38-Upgrade-Patch.zip
Movable Type Movable Type 4.361
-
Movable Type MT-4.38-Upgrade-Patch.zip
http://www.movabletype.org/downloads/patches/MT-4.38-Upgrade-Patch.zip
Movable Type Movable Type 4.36
-
Movable Type MT-4.38-Upgrade-Patch.zip
http://www.movabletype.org/downloads/patches/MT-4.38-Upgrade-Patch.zip
Movable Type Movable Type 4.23
-
Movable Type MT-4.38-Upgrade-Patch.zip
http://www.movabletype.org/downloads/patches/MT-4.38-Upgrade-Patch.zip
References
Movable Type Multiple SQL Injection and Command Injection Vulnerabilities
References:
References:
- Movable Type 4.38 patch to fix a known upgrading security issue (Movable Type)
- Movable Type Home Page (Six Apart)