Arbitrary Code Execution via Localization Template in Movable Type Pro and Open Source

Arbitrary Code Execution via Localization Template in Movable Type Pro and Open Source

CVE-2015-0845 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attackers to execute arbitrary code via vectors related to localization of templates.

Learn more about our Open Source Audit.