CVE-2010-3922: SQL Injection
Published Dec 9, 2010
·Updated
SQL injection vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
17 affected components
Sixapart Movabletype=4.33
Sixapart Movabletype=4.34
Sixapart Movabletype=4.0
Sixapart Movabletype=4.1
Sixapart Movabletype=4.32
Sixapart Movabletype=4.2
Sixapart Movabletype=4.26
Sixapart Movabletype=4.23
Sixapart Movabletype=4.25
Sixapart Movabletype=5.02
Sixapart Movabletype=4.3
Sixapart Movabletype=4.31
Sixapart Movabletype=5.01
Sixapart Movabletype=5.031
Sixapart Movabletype=4.261
Sixapart Movabletype=5.0-rc2
Sixapart Movabletype=5.03
Event History
Dec 9, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3922?
CVE-2010-3922 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2010-3922?
To remediate CVE-2010-3922, upgrade Movable Type to version 4.35 or higher for 4.x or to version 5.04 or higher for 5.x.
3
Which versions of Movable Type are affected by CVE-2010-3922?
CVE-2010-3922 affects Movable Type versions 4.x prior to 4.35 and 5.x prior to 5.04.
4
What type of attack does CVE-2010-3922 enable?
CVE-2010-3922 enables remote attackers to execute arbitrary SQL commands against vulnerable Movable Type instances.
5
Is there a workaround for CVE-2010-3922?
There are no official workarounds for CVE-2010-3922 other than applying the necessary updates or patches.