CVE-2012-1503

Sixapart Movable Type - XSS

Title source: rule
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.

Exploits (1)

exploitdb WORKING POC
by sqlhacker · textwebappsphp
https://www.exploit-db.com/exploits/22151

References (6)

Core 6
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/22151
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/86729
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/56160
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/79521

Scores

EPSS 0.0686
EPSS Percentile 91.5%

Details

CWE
CWE-79
Status published
Products (1)
sixapart/movable_type 5.13
Published Aug 29, 2014
Tracked Since Feb 18, 2026