Lucene search

K
cveMitreCVE-2014-9057
HistoryDec 16, 2014 - 6:59 p.m.

CVE-2014-9057

2014-12-1618:59:12
CWE-89
mitre
web.nvd.nist.gov
32
cve-2014-9057
sql injection
movable type
xml-rpc
vulnerability
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.3

Confidence

Low

EPSS

0.002

Percentile

52.5%

SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Affected configurations

Nvd
Node
debiandebian_linuxMatch7.0
Node
sixapartmovable_typeRange5.17
OR
sixapartmovable_typeMatch5.2
OR
sixapartmovable_typeMatch5.2.2
OR
sixapartmovable_typeMatch5.2.3
OR
sixapartmovable_typeMatch5.2.4
OR
sixapartmovable_typeMatch5.2.5
OR
sixapartmovable_typeMatch5.2.6
OR
sixapartmovable_typeMatch5.2.7
OR
sixapartmovable_typeMatch5.2.8
OR
sixapartmovable_typeMatch5.2.9
OR
sixapartmovable_typeMatch5.2.10
OR
sixapartmovable_typeMatch6.0
OR
sixapartmovable_typeMatch6.0.1
OR
sixapartmovable_typeMatch6.0.2
OR
sixapartmovable_typeMatch6.0.3
OR
sixapartmovable_typeMatch6.0.4
OR
sixapartmovable_typeMatch6.0.5
VendorProductVersionCPE
debiandebian_linux7.0cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
sixapartmovable_type*cpe:2.3:a:sixapart:movable_type:*:*:*:*:*:*:*:*
sixapartmovable_type5.2cpe:2.3:a:sixapart:movable_type:5.2:*:*:*:*:*:*:*
sixapartmovable_type5.2.2cpe:2.3:a:sixapart:movable_type:5.2.2:*:*:*:*:*:*:*
sixapartmovable_type5.2.3cpe:2.3:a:sixapart:movable_type:5.2.3:*:*:*:*:*:*:*
sixapartmovable_type5.2.4cpe:2.3:a:sixapart:movable_type:5.2.4:*:*:*:*:*:*:*
sixapartmovable_type5.2.5cpe:2.3:a:sixapart:movable_type:5.2.5:*:*:*:*:*:*:*
sixapartmovable_type5.2.6cpe:2.3:a:sixapart:movable_type:5.2.6:*:*:*:*:*:*:*
sixapartmovable_type5.2.7cpe:2.3:a:sixapart:movable_type:5.2.7:*:*:*:*:*:*:*
sixapartmovable_type5.2.8cpe:2.3:a:sixapart:movable_type:5.2.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 181

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.3

Confidence

Low

EPSS

0.002

Percentile

52.5%