GNU Mailman Admin Login Cross-Site Scripting Vulnerability
BID:4825
Info
GNU Mailman Admin Login Cross-Site Scripting Vulnerability
| Bugtraq ID: | 4825 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0388 |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Discovery of this issue is credited to "office". |
| Vulnerable: |
GNU Mailman 2.0.11 GNU Mailman 2.0.10 GNU Mailman 2.0.9 GNU Mailman 2.0.8 GNU Mailman 2.0.7 GNU Mailman 2.0.6 GNU Mailman 2.0.5 GNU Mailman 2.0.4 GNU Mailman 2.0.3 GNU Mailman 2.0.2 GNU Mailman 2.0.1 GNU Mailman 2.0 GNU Mailman 1.1 |
| Not Vulnerable: |
GNU Mailman 2.0.12 GNU Mailman 2.0.11 |
Discussion
GNU Mailman Admin Login Cross-Site Scripting Vulnerability
GNU Mailman is prone to a cross-site scripting vulnerability. An attacker may construct a malicious link to the administrative login page, which contains arbitrary HTML and script code.
A user visiting the link will have the attacker's script code executed in their web browser in the context of the site running the vulnerable software.
GNU Mailman is prone to a cross-site scripting vulnerability. An attacker may construct a malicious link to the administrative login page, which contains arbitrary HTML and script code.
A user visiting the link will have the attacker's script code executed in their web browser in the context of the site running the vulnerable software.