LWN.net Logo

movabletype-opensource: command/SQL injection

Package(s):movabletype-opensource CVE #(s):CVE-2013-0209
Created:January 22, 2013 Updated:January 23, 2013
Description: From the Debian advisory:

An input sanitation problem has been found in upgrade functions of movabletype-opensource, a web-based publishing platform. Using carefully crafted requests to the mt-upgrade.cgi file, it would be possible to inject OS command and SQL queries.

Alerts:
Debian DSA-2611-1 2013-01-22

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds