CVE-2012-1503: XSS
Published Aug 29, 2014
·Updated
Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.
Affected Software
1 affected component
Sixapart Movable Type=5.13
Event History
Aug 29, 2014
CVE Published
01:55 PM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1503?
CVE-2012-1503 is considered a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2012-1503?
To fix CVE-2012-1503, upgrade Movable Type Pro to a version higher than 5.13 that addresses this issue.
3
What software is affected by CVE-2012-1503?
CVE-2012-1503 affects Movable Type Pro version 5.13.
4
Can CVE-2012-1503 be exploited remotely?
Yes, CVE-2012-1503 can be exploited remotely by attackers through the comment section.
5
What type of vulnerability is CVE-2012-1503?
CVE-2012-1503 is classified as a cross-site scripting (XSS) vulnerability.