Vulnerabilities > CVE-2002-0388 - HTML Injection vulnerability in GNU Mailman Pipermail Index Summary

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
gnu
nessus
exploit available

Summary

Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries.

Exploit-Db

descriptionGNU Mailman 2.0.x Admin Login Cross-Site Scripting Vulnerability. CVE-2002-0388. Webapps exploit for cgi platform
idEDB-ID:21480
last seen2016-02-02
modified2002-05-20
published2002-05-20
reporteroffice
sourcehttps://www.exploit-db.com/download/21480/
titleGNU Mailman 2.0.x Admin Login Cross-Site Scripting Vulnerability

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-147.NASL
    descriptionA cross-site scripting vulnerability was discovered in mailman, a software to manage electronic mailing lists. When a properly crafted URL is accessed with Internet Explorer (other browsers don
    last seen2020-06-01
    modified2020-06-02
    plugin id14984
    published2004-09-29
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/14984
    titleDebian DSA-147-1 : mailman - XSS
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2002-125.NASL
    descriptionUpdated mailman packages are now available for Red Hat Linux Advanced Server. These updates resolve a cross-site scripting vulnerability present in versions of Mailman prior to 2.0.11. Two cross-site scripting vulnerabilities have been discovered in versions of Mailman prior to version 2.0.11.
    last seen2020-06-01
    modified2020-06-02
    plugin id12304
    published2004-07-06
    reporterThis script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/12304
    titleRHEL 2.1 : mailman (RHSA-2002:125)