|
|
| |
|
| |
movabletype-opensource: command/SQL injection
| Package(s): | movabletype-opensource |
CVE #(s): | CVE-2013-0209
|
| Created: | January 22, 2013 |
Updated: | January 23, 2013 |
| Description: |
From the Debian advisory:
An input sanitation problem has been found in upgrade functions of
movabletype-opensource, a web-based publishing platform. Using carefully
crafted requests to the mt-upgrade.cgi file, it would be possible to inject OS command and SQL queries. |
| Alerts: |
|
( Log in to post comments)
|
|
|