CVE-2003-0038
published 2003-02-07CVE-2003-0038: Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2)…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
4.72%
90.8th percentile
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | — | — |
| gnu | mailman | >= 0 < 2.1.1 | 2.1.1 |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mailman Cross-site scripting (XSS) vulnerability
ghsa·2022-04-29
CVE-2003-0038 [MEDIUM] CWE-79 Mailman Cross-site scripting (XSS) vulnerability
Mailman Cross-site scripting (XSS) vulnerability
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.
OSV
Mailman Cross-site scripting (XSS) vulnerability
osv·2022-04-29
CVE-2003-0038 [MEDIUM] Mailman Cross-site scripting (XSS) vulnerability
Mailman Cross-site scripting (XSS) vulnerability
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.
No detection rules found.
Exploit-DB
GNU Mailman 2.1 - 'email' Cross-Site Scripting
exploitdb·2003-01-24
CVE-2003-0038 GNU Mailman 2.1 - 'email' Cross-Site Scripting
GNU Mailman 2.1 - 'email' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/6677/info
A vulnerability has been discovered in GNU Mailman. It has been reported that Mailman is prone to cross site scripting attacks. This is due to insufficient santization of URI parameters.
As a result, attackers may embed malicious script code or HTML into a link to a site running the vulnerable software. If such a link is followed, the attacker-supplied code will be interpreted in the web browser of the victim of the attack. It may be possible to steal the unsuspecting user's cookie-based authentication credentials, as well as other sensitive information. Other attacks are also possible.
https://www.yourserver.com:443/mailman/options/yourlist?
language=en&email=alert('Can%20Cross%20S
Exploit-DB
GNU Mailman 2.1 - Error Page Cross-Site Scripting
exploitdb·2003-01-24
CVE-2003-0038 GNU Mailman 2.1 - Error Page Cross-Site Scripting
GNU Mailman 2.1 - Error Page Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/6678/info
A vulnerability has been discovered in GNU Mailman. The issue occurs to insufficient sanitization of user-supplied data which is output when generating error pages.
As a result, attackers may embed malicious script code or HTML into a link to a site running the vulnerable software. If such a link is followed, the attacker-supplied code will be interpreted in the web browser of the victim of the attack. It may be possible to steal the unsuspecting user's cookie-based authentication credentials, as well as other sensitive information. Other attacks are also possible.
It has been reported that GNU Mailman 2.0.11 is not affected by this issue.
https://www.yourserver.com:443//mailman/
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=104342745916111http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txthttp://www.debian.org/security/2004/dsa-436http://www.osvdb.org/9205http://www.securityfocus.com/bid/6677http://www.securitytracker.com/id?1005987https://exchange.xforce.ibmcloud.com/vulnerabilities/11152http://marc.info/?l=bugtraq&m=104342745916111http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txthttp://www.debian.org/security/2004/dsa-436http://www.osvdb.org/9205http://www.securityfocus.com/bid/6677http://www.securitytracker.com/id?1005987https://exchange.xforce.ibmcloud.com/vulnerabilities/11152
2003-02-07
Published