Record summary

CVE-2002-0855 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.

Description

Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBGNU Mailman 2.0.x - Subscribe Cross-Site ScriptingExploitDB exploitby officeNot analyzed1 file
ExploitDB

PoC details
ExploitDBGNU Mailman 2.0.x - Admin Login Variant Cross-Site ScriptingExploitDB exploitby officeNot analyzed1 file
ExploitDB

PoC details

References

11