Lucene search

K
freebsdFreeBSD64691C49-4B22-11E0-A226-00E0815B8DA8
HistoryFeb 13, 2011 - 12:00 a.m.

mailman -- XSS vulnerability

2011-02-1300:00:00
vuxml.freebsd.org
21

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.003

Percentile

71.1%

CVE reports:

Multiple cross-site scripting (XSS) vulnerabilities in
Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote
attackers to inject arbitrary web script or HTML via the (1)
full name or (2) username field in a confirmation message.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchmailman< 2.1.14_1UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.003

Percentile

71.1%