cvelist/2016/5xxx/CVE-2016-5742.json
2019-03-17 23:09:44 +00:00

82 lines
2.8 KiB
JSON

{
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2016-5742",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open Source 5.2.13 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "[oss-security] 20160622 Re: CVE request: SQL injection in MovableType xml-rpc interface",
"refsource": "MLIST",
"url": "http://www.openwall.com/lists/oss-security/2016/06/22/5"
},
{
"name": "1036160",
"refsource": "SECTRACK",
"url": "http://www.securitytracker.com/id/1036160"
},
{
"name": "[oss-security] 20160622 CVE request: SQL injection in MovableType xml-rpc interface",
"refsource": "MLIST",
"url": "http://www.openwall.com/lists/oss-security/2016/06/22/3"
},
{
"name": "https://movabletype.org/news/2016/06/movable_type_626_and_613_released.html",
"refsource": "CONFIRM",
"url": "https://movabletype.org/news/2016/06/movable_type_626_and_613_released.html"
},
{
"name": "[oss-security] 20160622 Re: CVE request: SQL injection in MovableType xml-rpc interface",
"refsource": "MLIST",
"url": "http://www.openwall.com/lists/oss-security/2016/06/22/6"
}
]
}
}