The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute arbitrary commands by leveraging the file-upload feature, related to an OS Command Injection issue.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Movable_type_open_source | Movabletype | * | 4.37 (including) |
Movable_type_open_source | Movabletype | 4.0 (including) | 4.0 (including) |
Movable_type_open_source | Movabletype | 4.0-beta (including) | 4.0-beta (including) |
Movable_type_open_source | Movabletype | 4.1 (including) | 4.1 (including) |
Movable_type_open_source | Movabletype | 4.1-beta (including) | 4.1-beta (including) |
Movable_type_open_source | Movabletype | 4.01-beta (including) | 4.01-beta (including) |
Movable_type_open_source | Movabletype | 4.2 (including) | 4.2 (including) |
Movable_type_open_source | Movabletype | 4.2-beta (including) | 4.2-beta (including) |
Movable_type_open_source | Movabletype | 4.3 (including) | 4.3 (including) |
Movable_type_open_source | Movabletype | 4.23 (including) | 4.23 (including) |
Movable_type_open_source | Movabletype | 4.25 (including) | 4.25 (including) |
Movable_type_open_source | Movabletype | 4.26 (including) | 4.26 (including) |
Movable_type_open_source | Movabletype | 4.31 (including) | 4.31 (including) |
Movable_type_open_source | Movabletype | 4.32 (including) | 4.32 (including) |
Movable_type_open_source | Movabletype | 4.33 (including) | 4.33 (including) |
Movable_type_open_source | Movabletype | 4.34 (including) | 4.34 (including) |
Movable_type_open_source | Movabletype | 4.35 (including) | 4.35 (including) |
Movable_type_open_source | Movabletype | 4.36 (including) | 4.36 (including) |
Movable_type_open_source | Movabletype | 4.261 (including) | 4.261 (including) |
Movable_type_open_source | Movabletype | 4.361 (including) | 4.361 (including) |
Movable_type_open_source | Movabletype | 5.1 (including) | 5.1 (including) |
Movable_type_open_source | Movabletype | 5.02 (including) | 5.02 (including) |
Movable_type_open_source | Movabletype | 5.03 (including) | 5.03 (including) |
Movable_type_open_source | Movabletype | 5.04 (including) | 5.04 (including) |
Movable_type_open_source | Movabletype | 5.05 (including) | 5.05 (including) |
Movable_type_open_source | Movabletype | 5.06 (including) | 5.06 (including) |
Movable_type_open_source | Movabletype | 5.11 (including) | 5.11 (including) |
Movable_type_open_source | Movabletype | 5.12 (including) | 5.12 (including) |
Movable_type_open_source | Movabletype | 5.031 (including) | 5.031 (including) |
Movable_type_open_source | Movabletype | 5.051 (including) | 5.051 (including) |
Movabletype-opensource | Ubuntu | lucid | * |
Movabletype-opensource | Ubuntu | maverick | * |
Movabletype-opensource | Ubuntu | natty | * |
Movabletype-opensource | Ubuntu | oneiric | * |
Movabletype-opensource | Ubuntu | precise | * |
Movabletype-opensource | Ubuntu | upstream | * |