Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_state parameter.
References
Configurations
Information
Published : 2015-03-27 07:59
Updated : 2015-03-27 10:43
NVD link : CVE-2013-2184
Mitre link : CVE-2013-2184
JSON object : View
CWE
CWE-17
DEPRECATED: Code
Products Affected
sixapart
- movable_type