Back

MEDIUM

security flaw

Published Jan 19, 2005

Description

Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of mailman shipped with Red Hat Enterprise Linux 2.1, 3, or 4. In addition, we believe this issue does not apply to the 2.0.x versions of mailman due to setting of STEALTH_MODE

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 19, 2005
Updated Aug 8, 2024
Reserved Dec 13, 2004
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jan 10, 2005
GHSA-RH6C-JH4C-9FG3