Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-0707

Опубликовано: 18 фев. 2011
Источник: redhat
CVSS2: 3.5
EPSS Низкий

Описание

Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=677375Mailman: Three XSS flaws due improper escaping of the full name of the member

EPSS

Процентиль: 85%
0.0246
Низкий

3.5 Low

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.

nvd
больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.

debian
больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py ...

github
около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.

oracle-oval
больше 14 лет назад

ELSA-2011-0308: mailman security update (MODERATE)

EPSS

Процентиль: 85%
0.0246
Низкий

3.5 Low

CVSS2