Movable Type (CVE-2010-3922) SQL注入漏洞

漏洞起因
输入验证错误
危险等级

 
影响系统
Movable Type Movable Type Open Source 4.34
Movable Type Movable Type Open Source 4.26
Movable Type Movable Type Open Source 4.25
Movable Type Movable Type Open Source 4.24
Movable Type Movable Type Open Source 4.23
Movable Type Movable Type Enterprise 4.34
Movable Type Movable Type Enterprise 4.26
Movable Type Movable Type Enterprise 4.25
Movable Type Movable Type Enterprise 4.24
Movable Type Movable Type Enterprise 4.23
Movable Type Movable Type Enterprise 4.22
Movable Type Movable Type Enterprise 4
Movable Type Movable Type 5.02
Movable Type Movable Type 5.01
Movable Type Movable Type 5.0
Movable Type Movable Type 4.34
Movable Type Movable Type 4.27
Movable Type Movable Type 4.261
Movable Type Movable Type 4.26
Movable Type Movable Type 4.25
Movable Type Movable Type 4.24
Movable Type Movable Type 4.23
Movable Type Movable Type 4.22
Movable Type Movable Type 4.21
Movable Type Movable Type 4.13
Movable Type Movable Type 4.01
Movable Type Movable Type 4
  
 
不受影响系统
Movable Type Movable Type Open Source 5.04
Movable Type Movable Type Open Source 4.35
Movable Type Movable Type Enterprise 4.35
Movable Type Movable Type 5.04
Movable Type Movable Type 4.35
 
危害
远程攻击者可以利用漏洞获取数据库敏感信息。
 
攻击所需条件
攻击者必须访问Movable Type。
 
漏洞信息
Movable Type是一款基于WEB的网络博客系统。
部分提交给Movable Type脚本的输入在用于SQL查询前缺少充分过滤,可通过注入任意SQL代码操作SQL查询,获取数据库敏感信息。
 
测试方法
 
厂商解决方案
用户可参考如下供应商提供的安全补丁信息:
Movable Type Movable Type Open Source 4.25
Movable Type MTOS-4.35-en.zip
http://www.movabletype.org/downloads/stable/MTOS-4.35-en.zip
Movable Type Movable Type Open Source 4.34
Movable Type MTOS-4.35-en.zip
http://www.movabletype.org/downloads/stable/MTOS-4.35-en.zip
Movable Type Movable Type Open Source 4.24
Movable Type MTOS-4.35-en.zip
http://www.movabletype.org/downloads/stable/MTOS-4.35-en.zip
Movable Type Movable Type Open Source 4.23
Movable Type MTOS-4.35-en.zip
http://www.movabletype.org/downloads/stable/MTOS-4.35-en.zip
Movable Type Movable Type Open Source 4.26
Movable Type MTOS-4.35-en.zip
http://www.movabletype.org/downloads/stable/MTOS-4.35-en.zip
 
漏洞提供者
Vendor

发表评论?

0 条评论。

发表评论