First published: Tue Dec 16 2014(Updated: )
SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/movabletype-opensource | ||
Debian Linux | =7.0 | |
Six Apart Movable Type | <=5.17 | |
Six Apart Movable Type | =5.2 | |
Six Apart Movable Type | =5.2.2 | |
Six Apart Movable Type | =5.2.3 | |
Six Apart Movable Type | =5.2.4 | |
Six Apart Movable Type | =5.2.5 | |
Six Apart Movable Type | =5.2.6 | |
Six Apart Movable Type | =5.2.7 | |
Six Apart Movable Type | =5.2.8 | |
Six Apart Movable Type | =5.2.9 | |
Six Apart Movable Type | =5.2.10 | |
Six Apart Movable Type | =6.0 | |
Six Apart Movable Type | =6.0.1 | |
Six Apart Movable Type | =6.0.2 | |
Six Apart Movable Type | =6.0.3 | |
Six Apart Movable Type | =6.0.4 | |
Six Apart Movable Type | =6.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9057 is classified as a critical vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2014-9057, upgrade Movable Type to version 6.0.6 or later, or apply any available patches provided by your vendor.
CVE-2014-9057 affects Movable Type versions prior to 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6.
Yes, CVE-2014-9057 can lead to data compromise as it permits execution of arbitrary SQL queries, potentially exposing sensitive data.
CVE-2014-9057 is a specific vulnerability in Movable Type's XML-RPC interface, making it particularly relevant to users of that software.