fml Mailing List HTML Injection Vulnerability
BID:3623
Info
fml Mailing List HTML Injection Vulnerability
| Bugtraq ID: | 3623 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 05 2001 12:00AM |
| Updated: | Dec 05 2001 12:00AM |
| Credit: | Posted in a Debian security advisory dated December 5, 2001. |
| Vulnerable: |
Ken'ichi Fukamachi flm 3.0 |
| Not Vulnerable: | |
Discussion
fml Mailing List HTML Injection Vulnerability
The fml Mailing List Server is a collection of perl scripts providing mailing list administration functionality for Linux and other systems. It includes support for a web based archive.
When index pages are created for these archives, the characters < and > are not properly escaped in email subject lines. This could lead to the injection of additional HTML tags, including the possibility of cross-site scripting attacks.
Earlier versions of flm may share this vulnerability.
The fml Mailing List Server is a collection of perl scripts providing mailing list administration functionality for Linux and other systems. It includes support for a web based archive.
When index pages are created for these archives, the characters < and > are not properly escaped in email subject lines. This could lead to the injection of additional HTML tags, including the possibility of cross-site scripting attacks.
Earlier versions of flm may share this vulnerability.
Exploit / POC
fml Mailing List HTML Injection Vulnerability
No exploit code is required to take advantage of this issue.
No exploit code is required to take advantage of this issue.
Solution / Fix
fml Mailing List HTML Injection Vulnerability
Solution:
Updated packages have been made available by Debian. The process of upgrading will automatically regenerate all index pages.
Ken'ichi Fukamachi flm 3.0
Solution:
Updated packages have been made available by Debian. The process of upgrading will automatically regenerate all index pages.
Ken'ichi Fukamachi flm 3.0
-
Debian 2.2 (all platforms) fml_3.0+beta.20000106-5_all.deb
http://security.debian.org/dists/stable/updates/main/binary-all/fml_3. 0+beta.20000106-5_all.deb
References
fml Mailing List HTML Injection Vulnerability
References:
References:
- "fml" Mailing List Server Package (Ken'ichi Fukamachi)