HOMEIT SecurityMeasures for Information Security VulnerabilitiesIPA/ISEC:Vulnerabilities:Security Alert for Vulnerability in Movable Type
Published: Dec 8, 2010
>> JAPANESE
Information-technology Promotion Agency, Japan (IPA, Chairman Kazumasa Fujie) has issued a security alert concerning security vulnerability in Movable Type on December 8, 2010.
This vulnerability could allow an attacker to manipulate the database, enabling the disclosure and/or deletion of the information held in the Movable Type system.
To fix this vulnerability, update the software to the fixed version provided by the product vendor.
Movable Type is developed by Six Apart, Ltd.which is a web content management system software to create and manage the content of websites and blogs. Movable Type is vulnerable to SQL injection due to a flaw in its database processing. If exploited, an attacker could disclose and/or delete the information held in the Movable Type system by manipulating the database.
To get a fixed version, go to the following URL:
http://www.sixapart.jp/movabletype/news/2010/12/08-1100.html (Japanese)
For the latest information, refer to the following URL:
http://jvndb.jvn.jp/jvndb/JVNDB-2010-000061
IPA received a report concerning this vulnerability and countermeasure directly from the product vendor on December 2, 2010, and released it today after JPCERT Coordination Center (JPCERT/CC) made adjustments with the vendor.
An attacker could manipulate the database, enabling the disclosure and/or deletion of the information held in the Movable Type system when the website is attacked by SQL injection.
To fix this vulnerability, update the software to the fixed version provided by the product vendor.
Severity Rating (CVSS base score) |
□ Low (0.0~3.9) |
■ Medium (4.0~6.9) |
□ High (7.0~10.0) |
---|---|---|---|
CVSS base score | 6.8 |
AV:Access Vector | □ Local | □ Adjacent Network |
■ Network |
---|---|---|---|
AC:Access Complexity | □ High | ■ Medium | □ Low |
Au:Authentication | □ Multiple | □ Single | ■ None |
C:Confidentiality Impact | □ None | ■ Partial | □ Complete |
I:Integrity Impact | □ None | ■ Partial | □ Complete |
A:Availability Impact | □ None | ■ Partial | □ Complete |
■:Selected Values
This vulnerability has been CWE classified as "SQL Injection (CWE-89)".
IT Security Center,
Information-technology Promotion Agency, Japan (ISEC/IPA)
E-mail: