CVE-2012-1262

EUVD-2012-1288
Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the dbuser parameter, a different vulnerability than CVE-2012-0318.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Affected Products (NVD)
VendorProductVersion
movabletypemovable_type_open_source
𝑥
≤ 4.37
movabletypemovable_type_open_source
4.0
movabletypemovable_type_open_source
4.0:beta
movabletypemovable_type_open_source
4.1
movabletypemovable_type_open_source
4.1:beta
movabletypemovable_type_open_source
4.01:beta
movabletypemovable_type_open_source
4.2
movabletypemovable_type_open_source
4.2:beta
movabletypemovable_type_open_source
4.3
movabletypemovable_type_open_source
4.23
movabletypemovable_type_open_source
4.25
movabletypemovable_type_open_source
4.26
movabletypemovable_type_open_source
4.31
movabletypemovable_type_open_source
4.32
movabletypemovable_type_open_source
4.33
movabletypemovable_type_open_source
4.34
movabletypemovable_type_open_source
4.35
movabletypemovable_type_open_source
4.36
movabletypemovable_type_open_source
4.261
movabletypemovable_type_open_source
4.361
movabletypemovable_type_open_source
5.1
movabletypemovable_type_open_source
5.02
movabletypemovable_type_open_source
5.03
movabletypemovable_type_open_source
5.04
movabletypemovable_type_open_source
5.05
movabletypemovable_type_open_source
5.06
movabletypemovable_type_open_source
5.11
movabletypemovable_type_open_source
5.12
movabletypemovable_type_open_source
5.031
movabletypemovable_type_open_source
5.051
movabletypemovable_type_enterprise
𝑥
≤ 4.37
movabletypemovable_type_enterprise
4.0
movabletypemovable_type_enterprise
4.0:beta
movabletypemovable_type_enterprise
4.1
movabletypemovable_type_enterprise
4.01:beta
movabletypemovable_type_enterprise
4.1:beta
movabletypemovable_type_enterprise
4.2
movabletypemovable_type_enterprise
4.2:beta
movabletypemovable_type_enterprise
4.3
movabletypemovable_type_enterprise
4.23
movabletypemovable_type_enterprise
4.25
movabletypemovable_type_enterprise
4.26
movabletypemovable_type_enterprise
4.31
movabletypemovable_type_enterprise
4.32
movabletypemovable_type_enterprise
4.33
movabletypemovable_type_enterprise
4.34
movabletypemovable_type_enterprise
4.35
movabletypemovable_type_enterprise
4.36
movabletypemovable_type_enterprise
4.261
movabletypemovable_type_enterprise
4.361
movabletypemovable_type_enterprise
5.1
movabletypemovable_type_enterprise
5.02
movabletypemovable_type_enterprise
5.03
movabletypemovable_type_enterprise
5.04
movabletypemovable_type_enterprise
5.05
movabletypemovable_type_enterprise
5.06
movabletypemovable_type_enterprise
5.11
movabletypemovable_type_enterprise
5.12
movabletypemovable_type_enterprise
5.031
movabletypemovable_type_enterprise
5.051
movabletypemovable_type_advanced
𝑥
≤ 4.37
movabletypemovable_type_advanced
4.0
movabletypemovable_type_advanced
4.0:beta
movabletypemovable_type_advanced
4.1
movabletypemovable_type_advanced
4.01:beta
movabletypemovable_type_advanced
4.1:beta
movabletypemovable_type_advanced
4.2
movabletypemovable_type_advanced
4.2:beta
movabletypemovable_type_advanced
4.3
movabletypemovable_type_advanced
4.23
movabletypemovable_type_advanced
4.25
movabletypemovable_type_advanced
4.26
movabletypemovable_type_advanced
4.31
movabletypemovable_type_advanced
4.32
movabletypemovable_type_advanced
4.33
movabletypemovable_type_advanced
4.34
movabletypemovable_type_advanced
4.35
movabletypemovable_type_advanced
4.36
movabletypemovable_type_advanced
4.261
movabletypemovable_type_advanced
4.361
movabletypemovable_type_advanced
5.1
movabletypemovable_type_advanced
5.02
movabletypemovable_type_advanced
5.03
movabletypemovable_type_advanced
5.04
movabletypemovable_type_advanced
5.05
movabletypemovable_type_advanced
5.06
movabletypemovable_type_advanced
5.11
movabletypemovable_type_advanced
5.12
movabletypemovable_type_advanced
5.031
movabletypemovable_type_advanced
5.051
movabletypemovable_type_pro
𝑥
≤ 4.37
movabletypemovable_type_pro
4.0
movabletypemovable_type_pro
4.0:beta
movabletypemovable_type_pro
4.1
movabletypemovable_type_pro
4.1:beta
movabletypemovable_type_pro
4.01:beta
movabletypemovable_type_pro
4.2
movabletypemovable_type_pro
4.2:beta
movabletypemovable_type_pro
4.3
movabletypemovable_type_pro
4.23
movabletypemovable_type_pro
4.25
movabletypemovable_type_pro
4.26
movabletypemovable_type_pro
4.31
movabletypemovable_type_pro
4.32
movabletypemovable_type_pro
4.33
movabletypemovable_type_pro
4.34
movabletypemovable_type_pro
4.35
movabletypemovable_type_pro
4.36
movabletypemovable_type_pro
4.261
movabletypemovable_type_pro
4.361
movabletypemovable_type_pro
5.1
movabletypemovable_type_pro
5.02
movabletypemovable_type_pro
5.03
movabletypemovable_type_pro
5.04
movabletypemovable_type_pro
5.05
movabletypemovable_type_pro
5.06
movabletypemovable_type_pro
5.11
movabletypemovable_type_pro
5.12
movabletypemovable_type_pro
5.031
movabletypemovable_type_pro
5.051
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
movabletype-opensource
hardy
dne
lucid
ignored
maverick
ignored
natty
ignored
oneiric
ignored
precise
ignored
quantal
not-affected
raring
not-affected
saucy
not-affected
trusty
dne
utopic
not-affected
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne