PT-2003-1325 · Gnu · Mailman
Manuel Rodriguez
·
Published
2003-01-29
·
Updated
2022-04-29
·
CVE-2003-0038
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Mailman version 2.1
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject script or HTML into web pages via the
email or language parameters.Recommendations
For Mailman version 2.1, update the options.py file to properly sanitize user input for the
email and language parameters to prevent XSS attacks.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mailman