CVE-2014-9057

SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Configurations

Configuration 1 (hide)

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:sixapart:movable_type:*:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:5.2:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:5.2.2:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:5.2.3:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:5.2.4:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:5.2.5:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:5.2.6:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:5.2.7:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:5.2.8:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:5.2.9:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:5.2.10:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:6.0:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:6.0.3:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:6.0.4:*:*:*:*:*:*:*
cpe:2.3:a:sixapart:movable_type:6.0.5:*:*:*:*:*:*:*

History

21 Nov 2024, 02:20

Type Values Removed Values Added
References () http://secunia.com/advisories/61227 - () http://secunia.com/advisories/61227 -
References () https://movabletype.org/documentation/appendices/release-notes/6.0.6.html - Vendor Advisory () https://movabletype.org/documentation/appendices/release-notes/6.0.6.html - Vendor Advisory
References () https://movabletype.org/news/2014/12/6.0.6.html - Vendor Advisory () https://movabletype.org/news/2014/12/6.0.6.html - Vendor Advisory
References () https://www.debian.org/security/2015/dsa-3183 - () https://www.debian.org/security/2015/dsa-3183 -

Information

Published : 2014-12-16 18:59

Updated : 2024-11-21 02:20


NVD link : CVE-2014-9057

Mitre link : CVE-2014-9057

CVE.ORG link : CVE-2014-9057


JSON object : View

Products Affected

debian

  • debian_linux

sixapart

  • movable_type
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')