CVE-2006-1712
published 2006-04-11CVE-2006-1712: Cross-site scripting (XSS) vulnerability in the private archive script (private.py) in GNU Mailman 2.1.7 allows remote attackers to inject arbitrary web script…
PriorityP412low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
1.40%
69.6th percentile
Cross-site scripting (XSS) vulnerability in the private archive script (private.py) in GNU Mailman 2.1.7 allows remote attackers to inject arbitrary web script or HTML via the action argument.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-0052 Mailman DoS, CVE-2006-1712 Mailman cross site scripting bug and CVE-2005-3573 Mailman Denial of Service (CVE-2005-4153); also CAN-2004-1177 Cross-site scripting (XSS) vulnerability
bugzilla·2006-06-02·CVSS 5.0
CVE-2006-0052 [MEDIUM] CVE-2006-0052 Mailman DoS, CVE-2006-1712 Mailman cross site scripting bug and CVE-2005-3573 Mailman Denial of Service (CVE-2005-4153); also CAN-2004-1177 Cross-site scripting (XSS) vulnerability
CVE-2006-0052 Mailman DoS, CVE-2006-1712 Mailman cross site scripting bug and CVE-2005-3573 Mailman Denial of Service (CVE-2005-4153); also CAN-2004-1177 Cross-site scripting (XSS) vulnerability
Mailman DoS allows remote attackers to cause a denial of service by using
multipart MIME message with a single part MIME message.
Mailman cross site scripting bug allows remote attackers to inject arbitrary web
script in the form ofaction argument.
In Mailman Denial of Service application crash and server message "fail with an
Overflow on bad date data in a processed message".
http://www.redhat.com/archives/fedora-test-list/2006-May/msg00131.html
http://www.redhat.com/archives/fedora-package-announce/2006-May/msg00134.htm
http://www.redhat.com/archives/fedora-package-announce/2006-May/msg00135.
Bugzilla
CVE-2006-1712 Mailman cross site scripting bug
bugzilla·2006-04-11·CVSS 2.6
CVE-2006-1712 [LOW] CVE-2006-1712 Mailman cross site scripting bug
CVE-2006-1712 Mailman cross site scripting bug
Mailman cross site scripting bug
Moritz Naumann discovered a cross site scripting bug in Mailman's
private archive script.
http://mail.python.org/pipermail/mailman-announce/2006-April/000084.html http://bugs.gentoo.org/show_bug.cgi?id=129136
Discussion:
Created attachment 127627
Patch extracted from the upstream tarballs
---
Please test:
http://www.redhat.com/archives/fedora-test-list/2006-May/msg00131.html
---
I am suspecting that this bug report is related to the mailman package that
was released in FEDORA-2006-535, mailman-2.1.8-0.FC5.1,
?
If so, should this bug be closed ERRATA?
---
Yes, this issue was fixed in FEDORA-2006-535.
http://bugs.gentoo.org/show_bug.cgi?id=129136http://mail.python.org/pipermail/mailman-announce/2006-April/000084.htmlhttp://secunia.com/advisories/19558http://securitytracker.com/id?1015876http://www.mail-archive.com/mailman-checkins%40python.org/msg06273.htmlhttp://www.osvdb.org/24442http://www.securityfocus.com/bid/17403http://www.vupen.com/english/advisories/2006/1269http://bugs.gentoo.org/show_bug.cgi?id=129136http://mail.python.org/pipermail/mailman-announce/2006-April/000084.htmlhttp://secunia.com/advisories/19558http://securitytracker.com/id?1015876http://www.mail-archive.com/mailman-checkins%40python.org/msg06273.htmlhttp://www.osvdb.org/24442http://www.securityfocus.com/bid/17403http://www.vupen.com/english/advisories/2006/1269
2006-04-11
Published