Candidate: CVE-2016-5742 PublicDate: 2017-01-23 21:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5742 https://movabletype.org/news/2016/06/movable_type_626_and_613_released.html http://www.openwall.com/lists/oss-security/2016/06/22/3 http://www.openwall.com/lists/oss-security/2016/06/22/6 Description: SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open Source 5.2.13 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: John Lightsey Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_movabletype-opensource: upstream_movabletype-opensource: needed precise_movabletype-opensource: ignored (reached end-of-life) precise/esm_movabletype-opensource: DNE (precise was needed) trusty_movabletype-opensource: ignored (reached end-of-life) trusty/esm_movabletype-opensource: DNE (trusty was needed) vivid/stable-phone-overlay_movabletype-opensource: DNE vivid/ubuntu-core_movabletype-opensource: DNE wily_movabletype-opensource: DNE xenial_movabletype-opensource: DNE yakkety_movabletype-opensource: DNE zesty_movabletype-opensource: DNE artful_movabletype-opensource: DNE bionic_movabletype-opensource: DNE cosmic_movabletype-opensource: DNE disco_movabletype-opensource: DNE devel_movabletype-opensource: DNE