CVE-2004-1177
published 2005-01-10CVE-2004-1177: Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.78%
76.0th percentile
Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | >= 0 < 2.1.5 | 2.1.5 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
mailman vulnerabilities
vendor_ubuntu·2005-01-11
CVE-2004-1177 mailman vulnerabilities
Title: mailman vulnerabilities
Summary: mailman vulnerabilities
Florian Weimer discovered a cross-site scripting vulnerability in
mailman's automatically generated error messages. An attacker could
craft an URL containing JavaScript (or other content embedded into
HTML) which triggered a mailman error page. When an unsuspecting user
followed this URL, the malicious content was copied unmodified to the
error page and executed in the context of this page.
Juha-Matti Tapio discovered an information disclosure in the private
rosters management. Everybody could check whether a specified email
address was subscribed to a private mailing list by looking at the
error message. This bug was Ubuntu/Debian specific.
Important note:
There is currently another known vulnerability: when an user
subs
Red Hat
security flaw
vendor_redhat·2005-01-10·CVSS 4.3
CVE-2004-1177 [MEDIUM] security flaw
security flaw
Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.
Statement: This issue did not affect the versions of mailman shipped with Red Hat Enterprise Linux 2.1, 3, or 4. In addition, we believe this issue does not apply to the 2.0.x versions of mailman due to setting of STEALTH_MODE
GHSA
mailman Cross-site scripting (XSS) vulnerability
ghsa·2022-04-29
CVE-2004-1177 [MEDIUM] CWE-79 mailman Cross-site scripting (XSS) vulnerability
mailman Cross-site scripting (XSS) vulnerability
Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.
OSV
mailman Cross-site scripting (XSS) vulnerability
osv·2022-04-29
CVE-2004-1177 [MEDIUM] mailman Cross-site scripting (XSS) vulnerability
mailman Cross-site scripting (XSS) vulnerability
Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2004-1177 security flaw
bugzilla·2018-08-16·CVSS 4.3
CVE-2004-1177 [MEDIUM] CVE-2004-1177 security flaw
CVE-2004-1177 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.
---
Statement:
This issue did not affect the versions of mailman shipped with Red Hat Enterprise Linux 2.1, 3, or 4. In addition, we believe this issue does not apply to the 2.0.x versions of mailman due to setting of STEALTH_MODE
Bugzilla
CVE-2006-0052 Mailman DoS, CVE-2006-1712 Mailman cross site scripting bug and CVE-2005-3573 Mailman Denial of Service (CVE-2005-4153); also CAN-2004-1177 Cross-site scripting (XSS) vulnerability
bugzilla·2006-06-02·CVSS 5.0
CVE-2006-0052 [MEDIUM] CVE-2006-0052 Mailman DoS, CVE-2006-1712 Mailman cross site scripting bug and CVE-2005-3573 Mailman Denial of Service (CVE-2005-4153); also CAN-2004-1177 Cross-site scripting (XSS) vulnerability
CVE-2006-0052 Mailman DoS, CVE-2006-1712 Mailman cross site scripting bug and CVE-2005-3573 Mailman Denial of Service (CVE-2005-4153); also CAN-2004-1177 Cross-site scripting (XSS) vulnerability
Mailman DoS allows remote attackers to cause a denial of service by using
multipart MIME message with a single part MIME message.
Mailman cross site scripting bug allows remote attackers to inject arbitrary web
script in the form ofaction argument.
In Mailman Denial of Service application crash and server message "fail with an
Overflow on bad date data in a processed message".
http://www.redhat.com/archives/fedora-test-list/2006-May/msg00131.html
http://www.redhat.com/archives/fedora-package-announce/2006-May/msg00134.htm
http://www.redhat.com/archives/fedora-package-announce/2006-May/msg00135.
Bugzilla
CVE-2004-1177 mailman
bugzilla·2005-08-02·CVSS 4.3
CVE-2004-1177 [MEDIUM] CVE-2004-1177 mailman
CVE-2004-1177 mailman
+++ This bug was initially created as a clone of Bug #147833 +++
Description of problem:
Missing XSS security patches for mailman-2.1.5 ?
Version-Release number of selected component (if applicable):
mailman-2.1.5-24.rhel3
Additional info:
It appears there was an XSS vuln in mailman thru version 2.1.5
that was patched by other vendors, but not yet patched in
RHEL to date(2005-02-11): [CAN-2004-1177] cross-site scripting in
/var/mailman/scripts/driver
See also:
https://bugzilla.ubuntu.com/show_bug.cgi?id=5057
http://www.securityfocus.com/bid/12243
Discussion:
This bug is the RHEL2.1 placeholder, please see the parent bug (bug 147833) for
more information.
---
Closing, we do not believe CAN-2004-1177 applies to the 2.0.x versions of
mailman due to setting of ST
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=287555http://marc.info/?l=bugtraq&m=110549296126351&w=2http://secunia.com/advisories/13603http://www.debian.org/security/2005/dsa-674http://www.mandriva.com/security/advisories?name=MDKSA-2005:015http://www.novell.com/linux/security/advisories/2005_07_mailman.htmlhttp://www.redhat.com/support/errata/RHSA-2005-235.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18854https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11113http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=287555http://marc.info/?l=bugtraq&m=110549296126351&w=2http://secunia.com/advisories/13603http://www.debian.org/security/2005/dsa-674http://www.mandriva.com/security/advisories?name=MDKSA-2005:015http://www.novell.com/linux/security/advisories/2005_07_mailman.htmlhttp://www.redhat.com/support/errata/RHSA-2005-235.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18854https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11113
2005-01-10
Published