CVE-2012-1497
Publication date 3 March 2012
Last updated 24 July 2024
Ubuntu priority
Description
The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files by leveraging the template-designer role.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| movabletype-opensource | ||
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |