CVE-2012-2644: XSS
Cross-site scripting (XSS) vulnerability in the MT4i plugin 3.1 beta 4 and earlier for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-2642.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2644?
CVE-2012-2644 is categorized as a cross-site scripting (XSS) vulnerability, which can allow attackers to inject malicious scripts into web pages.
How do I fix CVE-2012-2644?
To fix CVE-2012-2644, update the MT4i plugin to a version later than 3.1 beta 4, where the vulnerability has been addressed.
Which versions of the MT4i plugin are affected by CVE-2012-2644?
CVE-2012-2644 affects MT4i plugin version 3.1 beta 4 and earlier.
What types of attacks can CVE-2012-2644 facilitate?
CVE-2012-2644 can facilitate various attacks, including stealing session cookies and performing actions on behalf of users without their consent.
Is Movable Type itself affected by CVE-2012-2644?
No, Movable Type itself is not affected; the vulnerability is specific to the MT4i plugin.