CVE-2012-1262
Summary
| CVE | CVE-2012-1262 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-03-03 04:04:57 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the dbuser parameter, a different vulnerability than CVE-2012-0318. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Movable Type 5.13, 5.07, and 4.38 Security Updates | MovableType.org - Home of the MT Community | af854a3a-2127-422b-91ae-364da2661108 | www.movabletype.org | Patch, Vendor Advisory |
| Movable Type Flaws Permit Remote Authenticated Command Injection and Remote Cross-Site Scripting and Cross-Site Request Forgery Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| 404 Not Found | Trustwave | af854a3a-2127-422b-91ae-364da2661108 | www.trustwave.com | Exploit |
| Debian -- Security Information -- DSA-2423-1 movabletype-opensource | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Full Disclosure: TWSL2012-003: Cross-Site Scripting Vulnerability in Movable Type Publishing Platform | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Movable Type Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/79470 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Movable Type Publishing Platform Cross Site Scripting ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.org | |
| JVN#49836527: Movable Type vulnerable to cross-site scripting | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| jvndb.jvn.jp/jvndb/JVNDB-2012-000016 | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | |
| Movable Type 5.13, 5.07, and 4.38 Release Notes | MovableType.org - Home of the MT Community | af854a3a-2127-422b-91ae-364da2661108 | www.movabletype.org | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.