|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
|
Description |
Mailman contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unknown or unspecified variables upon submission to the private archive script. This can be exploited to execute arbitrary HTML and script code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Rumored / Private
Disclosure:
OSVDB Verified
OSVDB:
Web Related
|
|
Solution |
Upgrade to version 2.1.8rc1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
Mailman
 |
2.1.7 |
|
|
|
|
|
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|