CVE-2012-1262
Movabletype Movable Type Open Source < 4.37 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the dbuser parameter, a different vulnerability than CVE-2012-0318.
References (13)
Scores
EPSS
0.0085
EPSS Percentile
74.7%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
movabletype/movable_type_open_source
< 4.37
movabletype/movable_type_open_source
movabletype/movable_type_open_source
movabletype/movable_type_open_source
movabletype/movable_type_open_source
movabletype/movable_type_open_source
movabletype/movable_type_open_source
movabletype/movable_type_open_source
movabletype/movable_type_open_source
movabletype/movable_type_open_source
movabletype/movable_type_open_source
movabletype/movable_type_open_source
movabletype/movable_type_open_source
movabletype/movable_type_open_source
movabletype/movable_type_open_source
... and 35 more
Timeline
Published
Mar 03, 2012
Tracked Since
Feb 18, 2026