Lucene search

K
cve[email protected]CVE-2003-0965
HistoryFeb 17, 2004 - 5:00 a.m.

CVE-2003-0965

2004-02-1705:00:00
web.nvd.nist.gov
33
cve-2003-0965
mailman
xss
vulnerability
cgi
session cookies
unauthorized activities

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

5.5 Medium

AI Score

Confidence

High

0.02 Low

EPSS

Percentile

89.0%

Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.

Affected configurations

NVD
Node
gnumailmanRange2.1.4
CPENameOperatorVersion
gnu:mailmangnu mailmanle2.1.4

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

5.5 Medium

AI Score

Confidence

High

0.02 Low

EPSS

Percentile

89.0%