CVE-2013-2184: High severity six apart movable type vulnerability
Published Jun 17, 2013
·Updated
Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the commentstate parameter.
Affected Software
3 affected componentsFixes available
debian/movabletype-opensource
debian/movabletype-opensource<=5.1.4+dfsg-4, <=5.1.4+dfsg-5
5.1.4+dfsg-4+deb7u2
Sixapart Movable Type<=5.2.5
Event History
Mar 27, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2184?
CVE-2013-2184 is considered to have a high severity due to its potential for remote code execution.
2
How do I fix CVE-2013-2184?
To fix CVE-2013-2184, upgrade Movable Type to version 5.2.6 or later.
3
Which versions of Movable Type are affected by CVE-2013-2184?
CVE-2013-2184 affects Movable Type versions prior to 5.2.6.
4
Can CVE-2013-2184 be exploited by attackers?
Yes, CVE-2013-2184 can be exploited by remote attackers to execute arbitrary code.
5
What components are vulnerable in CVE-2013-2184?
CVE-2013-2184 primarily involves the improper use of the Storable::thaw function in the Movable Type application.