Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-2184

Опубликовано: 27 мар. 2015
Источник: debian

Описание

Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_state parameter.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
movabletype-opensourcefixed5.2.7+dfsg-1package
movabletype-opensourceno-dsasqueezepackage

Примечания

  • http://seclists.org/oss-sec/2013/q2/568

  • http://www.movabletype.org/documentation/appendices/release-notes/movable-type-526-release-notes.html

Связанные уязвимости

ubuntu
почти 11 лет назад

Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_state parameter.

nvd
почти 11 лет назад

Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_state parameter.

github
больше 3 лет назад

Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_state parameter.