20020724 cross-site scripting bug of Mailmanmailing list
http://archives.neohapsis.com/archives/bugtraq/2002-07/0268.html CVE-2002-0855
GNU Mailman 2.0.x - Subscribe Cross-Site Scripting
Record summary
CVE-2002-0855 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.
Description
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBGNU Mailman 2.0.x - Subscribe Cross-Site ScriptingExploitDB exploitby officeNot analyzed1 file
ExploitDBGNU Mailman 2.0.x - Admin Login Variant Cross-Site ScriptingExploitDB exploitby officeNot analyzed1 file
References
11CLA-2002:522Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000522 mail.python.orgConfirmation
http://mail.python.org/pipermail/mailman-announce/2002-July/000043.html DSA-147Vendor advisory
http://www.debian.org/security/2002/dsa-147 mailman-subscription-option-xss(9985)vdb entry
http://www.iss.net/security_center/static/9985.php RHSA-2002:176Vendor advisory
http://www.redhat.com/support/errata/RHSA-2002-176.html RHSA-2002:177Vendor advisory
http://www.redhat.com/support/errata/RHSA-2002-177.html RHSA-2002:178Vendor advisory
http://www.redhat.com/support/errata/RHSA-2002-178.html RHSA-2002:181Vendor advisory
http://www.redhat.com/support/errata/RHSA-2002-181.html 5298vdb entry
http://www.securityfocus.com/bid/5298 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0855