Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5742

Опубликовано: 23 янв. 2017
Источник: debian
EPSS Низкий

Описание

SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open Source 5.2.13 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
movabletype-opensourceremovedpackage

Примечания

  • https://movabletype.org/news/2016/06/movable_type_626_and_613_released.html

  • https://www.openwall.com/lists/oss-security/2016/06/22/3

  • https://github.com/movabletype/movabletype/commit/42113544e7d8ebf6064b7b01b921734b667a1682

EPSS

Процентиль: 77%
0.01022
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open Source 5.2.13 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 9.8
nvd
около 9 лет назад

SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open Source 5.2.13 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 9.8
github
больше 3 лет назад

SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open Source 5.2.13 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS

Процентиль: 77%
0.01022
Низкий