Back to Database
Status published
High
CVE-2013-2184
Movable Type before 5.2.6 does not properly use the Storable::thaw...
Vulnerability Description
Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_state parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-2184
Credits & Attribution
No credits recorded in the NVD database.
References
More from sixapart
View All →CVE-2016-5742
SQL injection vulnerability in the XML-RPC interface in Movable Type...
Critical
9.8
CVE-2015-0845
Format string vulnerability in Movable Type Pro, Open Source, and...
High
7.5
CVE-2014-5313
Cross-site scripting (XSS) vulnerability in the management page in Six...
Low
3.5
CVE-2014-0977
Cross-site scripting (XSS) vulnerability in the Rich Text Editor in...
Medium
4.3
CVE-2013-0209
lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through...
High
7.5
Affected Vendor
sixapart
View all reports →Affected Software
movable type
Vulnerable Versions:
0
Timeline
Official Publish:
March 27th, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.