Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_state parameter.
This entry has been deprecated. It was originally used for organizing the Development View (CWE-699) and some other views, but it introduced unnecessary complexity and depth to the resulting tree.
Link | Tags |
---|---|
http://seclists.org/oss-sec/2013/q2/568 | mailing list |
https://movabletype.org/documentation/appendices/release-notes/movable-type-526-release-notes.html | vendor advisory |
http://seclists.org/oss-sec/2013/q2/560 | mailing list |
http://www.debian.org/security/2015/dsa-3183 | vendor advisory |