CVE-2012-1503
UnknownEPSS 2.01%
Last modified
CVE-2012-1503 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.. EPSS estimates a 2.01% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sixapart | Movable Type | 5.13 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-1503?
Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.
How severe is CVE-2012-1503?
Severity scoring for CVE-2012-1503 is pending analysis. The EPSS model estimates a 2.01% probability of exploitation in the next 30 days.
How do I fix CVE-2012-1503?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-1497The default configuration of Movable Type before 4.38, 5.0x …
- CVE-2012-1498Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2012-1499The JPEG 2000 codec (jp2.c) in OpenJPEG before 1.5 allows re…
- CVE-2012-1500Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4…5.4
- CVE-2012-1501Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2012-1502Double free vulnerability in the PyPAM_conv in PAMmodule.c i…
- CVE-2012-1506SQL injection vulnerability in the updateStatus function in …
- CVE-2012-1507Multiple cross-site scripting (XSS) vulnerabilities in Orang…
- CVE-2012-1508The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VM…
- CVE-2012-1509Buffer overflow in the XPDM display driver in VMware View be…
- CVE-2012-1510Buffer overflow in the WDDM display driver in VMware ESXi 4.…
- CVE-2012-1511Cross-site scripting (XSS) vulnerability in View Manager Por…
Are you affected by CVE-2012-1503?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
