First published: Sat Mar 03 2012(Updated: )
Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the dbuser parameter, a different vulnerability than CVE-2012-0318.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Movable Type Open Source | <=4.37 | |
Movable Type Open Source | =4.0 | |
Movable Type Open Source | =4.0-beta | |
Movable Type Open Source | =4.1 | |
Movable Type Open Source | =4.1-beta | |
Movable Type Open Source | =4.01-beta | |
Movable Type Open Source | =4.2 | |
Movable Type Open Source | =4.2-beta | |
Movable Type Open Source | =4.3 | |
Movable Type Open Source | =4.23 | |
Movable Type Open Source | =4.25 | |
Movable Type Open Source | =4.26 | |
Movable Type Open Source | =4.31 | |
Movable Type Open Source | =4.32 | |
Movable Type Open Source | =4.33 | |
Movable Type Open Source | =4.34 | |
Movable Type Open Source | =4.35 | |
Movable Type Open Source | =4.36 | |
Movable Type Open Source | =4.261 | |
Movable Type Open Source | =4.361 | |
Movable Type Open Source | =5.1 | |
Movable Type Open Source | =5.02 | |
Movable Type Open Source | =5.03 | |
Movable Type Open Source | =5.04 | |
Movable Type Open Source | =5.05 | |
Movable Type Open Source | =5.06 | |
Movable Type Open Source | =5.11 | |
Movable Type Open Source | =5.12 | |
Movable Type Open Source | =5.031 | |
Movable Type Open Source | =5.051 | |
Movable Type | <=4.37 | |
Movable Type | =4.0 | |
Movable Type | =4.0-beta | |
Movable Type | =4.1 | |
Movable Type | =4.01-beta | |
Movable Type | =4.1-beta | |
Movable Type | =4.2 | |
Movable Type | =4.2-beta | |
Movable Type | =4.3 | |
Movable Type | =4.23 | |
Movable Type | =4.25 | |
Movable Type | =4.26 | |
Movable Type | =4.31 | |
Movable Type | =4.32 | |
Movable Type | =4.33 | |
Movable Type | =4.34 | |
Movable Type | =4.35 | |
Movable Type | =4.36 | |
Movable Type | =4.261 | |
Movable Type | =4.361 | |
Movable Type | =5.1 | |
Movable Type | =5.02 | |
Movable Type | =5.03 | |
Movable Type | =5.04 | |
Movable Type | =5.05 | |
Movable Type | =5.06 | |
Movable Type | =5.11 | |
Movable Type | =5.12 | |
Movable Type | =5.031 | |
Movable Type | =5.051 | |
Movable Type | <=4.37 | |
Movable Type | =4.0 | |
Movable Type | =4.0-beta | |
Movable Type | =4.1 | |
Movable Type | =4.01-beta | |
Movable Type | =4.1-beta | |
Movable Type | =4.2 | |
Movable Type | =4.2-beta | |
Movable Type | =4.3 | |
Movable Type | =4.23 | |
Movable Type | =4.25 | |
Movable Type | =4.26 | |
Movable Type | =4.31 | |
Movable Type | =4.32 | |
Movable Type | =4.33 | |
Movable Type | =4.34 | |
Movable Type | =4.35 | |
Movable Type | =4.36 | |
Movable Type | =4.261 | |
Movable Type | =4.361 | |
Movable Type | =5.1 | |
Movable Type | =5.02 | |
Movable Type | =5.03 | |
Movable Type | =5.04 | |
Movable Type | =5.05 | |
Movable Type | =5.06 | |
Movable Type | =5.11 | |
Movable Type | =5.12 | |
Movable Type | =5.031 | |
Movable Type | =5.051 | |
Movable Type | <=4.37 | |
Movable Type | =4.0 | |
Movable Type | =4.0-beta | |
Movable Type | =4.1 | |
Movable Type | =4.1-beta | |
Movable Type | =4.01-beta | |
Movable Type | =4.2 | |
Movable Type | =4.2-beta | |
Movable Type | =4.3 | |
Movable Type | =4.23 | |
Movable Type | =4.25 | |
Movable Type | =4.26 | |
Movable Type | =4.31 | |
Movable Type | =4.32 | |
Movable Type | =4.33 | |
Movable Type | =4.34 | |
Movable Type | =4.35 | |
Movable Type | =4.36 | |
Movable Type | =4.261 | |
Movable Type | =4.361 | |
Movable Type | =5.1 | |
Movable Type | =5.02 | |
Movable Type | =5.03 | |
Movable Type | =5.04 | |
Movable Type | =5.05 | |
Movable Type | =5.06 | |
Movable Type | =5.11 | |
Movable Type | =5.12 | |
Movable Type | =5.031 | |
Movable Type | =5.051 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1262 has a severity rating of medium as it allows for cross-site scripting attacks in vulnerable versions of Movable Type.
To fix CVE-2012-1262, upgrade your Movable Type installation to version 4.38 or later for the Open Source editions or 5.07 or later for other editions.
CVE-2012-1262 affects Movable Type versions before 4.38, 5.0x before 5.07, and 5.1x before 5.13.
The attack vector for CVE-2012-1262 is through the dbuser parameter, which can be used to inject arbitrary web scripts or HTML.
No specific patch is available; users must upgrade to a newer version of Movable Type to mitigate the vulnerability.