« Volver al listado

CVE-2013-0209

Estado: ModificadaAlta (7.5)—

lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-0209",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-01-23T01:55:01.150",
  "references": [
    {
      "url": "http://openwall.com/lists/oss-security/2013/01/22/3",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.movabletype.org/2013/01/movable_type_438_patch.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.sec-1.com/blog/?p=402",
      "tags": [
        "Exploit"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.sec-1.com/blog/wp-content/uploads/2013/01/movabletype_upgrade_exec.rb_.txt",
      "tags": [
        "Exploit"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2013/01/22/3",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.movabletype.org/2013/01/movable_type_438_patch.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.sec-1.com/blog/?p=402",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.sec-1.com/blog/wp-content/uploads/2013/01/movabletype_upgrade_exec.rb_.txt",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code."
    },
    {
      "lang": "es",
      "value": "lib/MT/Upgrade.pm en mt-upgrade.cgi en Movable Type v4.2x y v4.3x hasta v4.38 no requiere autenticación para las peticiones a las funciones de migración de base de datos, lo que permite a atacantes remotos llevar a cabo  inyecciones eval y ataques de inyección SQL a través de parámetros especialmente elaborados, como se demuestra por un ataque de inyección eval contra la función core_drop_meta_for_table, dando lugar a la ejecución de código Perl."
    }
  ],
  "lastModified": "2026-06-16T23:48:58.330",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.21:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7AD39A71-0B61-4319-BEE1-12CAD4B095A1"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.22:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E36DD87F-F918-4BDD-98B7-41527470B838"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.23:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B49D8B0-39C9-480B-9471-1846CE5A2142"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.24:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F909511A-D7B6-4033-AB99-87D6BC5741F8"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.25:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A200E33-641A-41B3-8EB3-E7380B686C8C"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.26:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52311931-CE3A-487B-B153-4066D07F63E8"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.27:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86ED3B93-8769-4A60-BAE4-C50483254905"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.28:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "703EEB4B-4747-45D5-9335-6FD5CB238F13"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.28:*:enterprise:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A2BA875-0C6E-4AD4-9271-CB31E2B2B072"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.28:*:open_source:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BAAD088A-29B4-44B4-BB90-6BEF55428902"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.29:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36E48EE7-3212-406E-80AB-26B0206E97E3"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.29:*:enterprise:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59DC45AB-BF7F-4817-A0FB-E3EBCA8CB761"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.29:*:open_source:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6DE4CBB7-14AE-45F4-9170-3C097844E8DA"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4E3F7E4-FD59-49B2-96B8-EF8AFEB1E01A"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.32:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA5666EE-4383-417D-871F-480093A6A49D"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.33:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F273F33D-A680-4FCE-A80A-38D9BC98A7FF"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.34:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C23010F-2AEF-4574-A857-7F41F082F707"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.35:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1ADC65FF-B4E8-4346-80DE-647BDC4A4D3C"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.36:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8E76C88-E486-4463-BA41-6A08ECC5E214"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.37:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93798CD5-1099-4B6A-9303-6EFD037F5B11"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.38:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B053E3DC-BE9E-4AA5-90B6-362E4F4953C3"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.261:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4905997-E4CE-406D-BE0F-B5E2F87AA177"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.291:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "45A49069-F509-4C30-BC9F-DB1FF7C39294"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.291:*:enterprise:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B516CE7A-7751-4CE0-8E16-097058A6657D"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.291:*:open_source:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "320C5974-DA38-443F-9BAF-C60E729D3148"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.292:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E7330A56-5D69-495B-B0E9-A820B70573C5"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.292:*:enterprise:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "563F69FA-34DD-4BF3-9B94-D41848E13915"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.292:*:open_source:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7020769D-803A-473A-8F1A-4984F870D6B3"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.361:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9951EF1D-0D13-4215-9066-C17B352E6C6F"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.36:*:open_source:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CD6E7E17-E69C-43C7-A9E3-1A7339B8BF68"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.37:*:open_source:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "691C9C90-E88D-4E6F-A1DD-413FC73B9EF2"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.38:*:open_source:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7F06FE8-50EF-4838-B1C5-2D347AC4B4E3"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:4.361:*:open_source:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85FA0AB7-78D6-42DC-83E7-9630BD8EFCD0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}