From 004a3440aba5a8792d2f9adfa030c0f885a3ca9b Mon Sep 17 00:00:00 2001 From: brian d foy Date: Fri, 8 Mar 2024 20:10:16 -0500 Subject: [PATCH] Parallel change for #144 --- cpansa/CPANSA-MT.yml | 16 ---------------- 1 file changed, 16 deletions(-) diff --git a/cpansa/CPANSA-MT.yml b/cpansa/CPANSA-MT.yml index af86f05..df45624 100644 --- a/cpansa/CPANSA-MT.yml +++ b/cpansa/CPANSA-MT.yml @@ -323,22 +323,6 @@ advisories: - http://seclists.org/oss-sec/2013/q2/560 reported: 2015-03-27 severity: ~ -- affected_versions: '>=4.20,<4.38' - cves: - - CVE-2013-0209 - description: | - lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code. - fixed_versions: ~ - github_security_advisory: - - GHSA-qhr8-p6mw-gmf5 - id: CPANSA-MT-2013-0209 - references: - - http://www.sec-1.com/blog/wp-content/uploads/2013/01/movabletype_upgrade_exec.rb_.txt - - http://www.movabletype.org/2013/01/movable_type_438_patch.html - - http://openwall.com/lists/oss-security/2013/01/22/3 - - http://www.sec-1.com/blog/?p=402 - reported: 2013-01-23 - severity: ~ - affected_versions: =5.13 cves: - CVE-2012-1503