CVE-2006-3636
published 2006-09-06CVE-2006-3636: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified…
PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
6.42%
92.9th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | >= 0 < 1:2.1.10~b3-1 | 1:2.1.10~b3-1 |
| mailman | mailman | <= 2.1.10b | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gh24-6437-cg34: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2
ghsa_unreviewed·2022-05-01
CVE-2006-3636 [MEDIUM] GHSA-gh24-6437-cg34: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA
GHSA-qrw2-cc7v-xx92: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2
ghsa_unreviewed·2022-05-01·CVSS 6.8
CVE-2008-0564 [MEDIUM] CWE-79 GHSA-qrw2-cc7v-xx92: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) editing templates and (2) the list's "info attribute" in the web administrator interface, a different vulnerability than CVE-2006-3636.
OSV
CVE-2008-0564: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2
osv·2008-02-05·CVSS 6.8
CVE-2008-0564 [MEDIUM] CVE-2008-0564: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) editing templates and (2) the list's "info attribute" in the web administrator interface, a different vulnerability than CVE-2006-3636.
Red Hat
mailman: XSS triggerable by list administrator
vendor_redhat·2008-01-03·CVSS 6.8
CVE-2008-0564 [MEDIUM] CWE-79 mailman: XSS triggerable by list administrator
mailman: XSS triggerable by list administrator
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) editing templates and (2) the list's "info attribute" in the web administrator interface, a different vulnerability than CVE-2006-3636.
Package: mailman (Red Hat Enterprise Linux 6) - Not affected
Ubuntu
mailman vulnerabilities
vendor_ubuntu·2006-09-13·CVSS 5.0
CVE-2006-3636 [MEDIUM] mailman vulnerabilities
Title: mailman vulnerabilities
Summary: mailman vulnerabilities
Steve Alexander discovered that mailman did not properly handle
attachments with special filenames. A remote user could exploit that
to stop mail delivery until the server administrator manually cleaned
these posts. (CVE-2006-2941)
Various cross-site scripting vulnerabilities have been reported by
Barry Warsaw. By using specially crafted email addresses, names, and
similar arbitrary user-defined strings, a remote attacker could
exploit this to run web script code in the list administrator's
web browser. (CVE-2006-3636)
URLs logged to the error log file are now checked for invalid
characters. Before, specially crafted URLs could inject arbitrary
messages into the log.
Instructions: In general, a standard system upgrade is
Red Hat
security flaw
vendor_redhat·2006-09-04·CVSS 6.8
CVE-2006-3636 [MEDIUM] security flaw
security flaw
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
No detection rules found.
Bugzilla
CVE-2006-3636 security flaw
bugzilla·2018-08-16·CVSS 6.8
CVE-2006-3636 [MEDIUM] CVE-2006-3636 security flaw
CVE-2006-3636 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Bugzilla
CVE-2008-0564 mailman: XSS triggerable by list administrator
bugzilla·2008-02-05·CVSS 6.8
CVE-2008-0564 [MEDIUM] CVE-2008-0564 mailman: XSS triggerable by list administrator
CVE-2008-0564 mailman: XSS triggerable by list administrator
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-0564 to the following vulnerability:
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before
2.1.10b1 allow remote attackers to inject arbitrary web script or HTML
via unspecified vectors related to (1) editing templates and (2) the
list's "info attribute" in the web administrator interface, a
different vulnerability than CVE-2006-3636.
References:
http://mail.python.org/pipermail/mailman-announce/2008-February/000096.html
Discussion:
Created attachment 293989
Patch against mailman 2.1.9
Patch was provided by mailman upstream developer, Mark Sapiro.
---
mailman-2.1.9-8.2.fc8 has been pushed to the Fedora 8 testing repository. If problems st
Bugzilla
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
bugzilla·2006-10-20·CVSS 5.0
CVE-2006-4624 [MEDIUM] CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
+++ This bug was initially created as a clone of Bug #209891 +++
Cloning for FC3.
+++ This bug was initially created as a clone of Bug #206607 +++
FC6 needs mailman 2.1.9 to correct CVE-2006-4624, CVE-2006-3636, CVE-2006-2941
This bug is for FC3 and FC4. Upgrading to mailman 2.1.9 will correct these
vulnerabilities.
Discussion:
Oh okay. I guess I thought it was simpler to track a single issue in
just one bug report, but I guess splitting them out may help ... ? I
hope it does.
---
The current version of the .src.rpm is
mailman-2.1.5-32.fc3.src.rpm
at
---
Can someone check the src.rpm I made with the lateest mailman from legacy and
the patches from RHEL?
http://bugs.unl.edu.ar/~martin/mailman-2.1.5-33.fc3.legacy
Bugzilla
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
bugzilla·2006-10-07·CVSS 5.0
CVE-2006-4624 [MEDIUM] CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
+++ This bug was initially created as a clone of Bug #206607 +++
FC6 needs mailman 2.1.9 to correct CVE-2006-4624, CVE-2006-3636, CVE-2006-2941
This bug is for FC3 and FC4. Upgrading to mailman 2.1.9 will correct these
vulnerabilities.
Discussion:
In a fedora-legacy-list message (),
Martin Marques submitted mailman-2.1.8-1.FC4.1.legacy.src.rpm:
http://bugs.unl.edu.ar/~martin/mailman-2.1.8-1.FC4.1.legacy.src.rpm
This will need to be reviewed and packages built for updates-testing.
Work also needs to be done in the FC3 version of this bug, Bug #211676.
---
Fedora Core 4 is now completely unmaintained. These bugs can't be fixed in that
version. If the issue still persists in current Fedora Core, please reopen.
Thank yo
Bugzilla
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
bugzilla·2006-09-15·CVSS 5.0
CVE-2006-4624 [MEDIUM] CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
FC6 needs mailman 2.1.9 to correct CVE-2006-4624, CVE-2006-3636, CVE-2006-2941
Bugzilla
CVE-2006-4624 mailman logfile CRLF injection
bugzilla·2006-09-07·CVSS 5.0
CVE-2006-4624 [MEDIUM] CVE-2006-4624 mailman logfile CRLF injection
CVE-2006-4624 mailman logfile CRLF injection
mailman logfile CRLF injection
Text taken from MITRE:
CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1
allows remote attackers to spoof messages in the error log and
possibly trick the administrator into visiting malicious URLs via a
carriage return/line feed sequences in the URI.
The fix for this issue is here:
http://svn.sourceforge.net/viewvc/mailman/?revision=7918&view=rev
Discussion:
Bug #206607 also lists these two additional CVE's: CVE-2006-3636 CVE-2006-2941.
The solution for FC6Test3 was to upgrade to mailman 2.1.9. Any plans to do
likewise for this bug as well?
Those issues bring the current FC5 mailman to a security impact of "moderate,"
I believe?
---
The version 2.1.9 is available in FC-5 updates.
Bugzilla
CVE-2006-3636 Mailman XSS issues
bugzilla·2006-08-23·CVSS 6.8
CVE-2006-3636 [MEDIUM] CVE-2006-3636 Mailman XSS issues
CVE-2006-3636 Mailman XSS issues
Barry Warsaw reported some cross-site scripting (XSS) issues that affect mailman
prior to 2.1.9. I've verified that at least one of these issues is real.
Whilst it's not a conventional easy to exploit XSS, a user could modify their
entry in such a way that a XSS could run when a logged-in administrator views
that users details.
Discussion:
Created attachment 134698
Proposed patch from Barry Warsaw
---
public, removing embargo
http://sourceforge.net/project/shownotes.php?group_id=103&release_id=444295
http://secunia.com/advisories/21732
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find t
http://mail.python.org/pipermail/mailman-announce/2006-September/000087.htmlhttp://moritz-naumann.com/adv/0013/mailmanmulti/0013.txthttp://rhn.redhat.com/errata/RHSA-2006-0600.htmlhttp://secunia.com/advisories/21732http://secunia.com/advisories/21792http://secunia.com/advisories/21879http://secunia.com/advisories/22011http://secunia.com/advisories/22020http://secunia.com/advisories/22227http://secunia.com/advisories/22639http://security.gentoo.org/glsa/glsa-200609-12.xmlhttp://securitytracker.com/id?1016808http://sourceforge.net/project/shownotes.php?group_id=103&release_id=444295http://www.debian.org/security/2006/dsa-1188http://www.mandriva.com/security/advisories?name=MDKSA-2006:165http://www.novell.com/linux/security/advisories/2006_25_sr.htmlhttp://www.securityfocus.com/archive/1/445992/100/0/threadedhttp://www.securityfocus.com/bid/19831http://www.securityfocus.com/bid/20021http://www.ubuntu.com/usn/usn-345-1http://www.vupen.com/english/advisories/2006/3446https://exchange.xforce.ibmcloud.com/vulnerabilities/28731https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10553http://mail.python.org/pipermail/mailman-announce/2006-September/000087.htmlhttp://moritz-naumann.com/adv/0013/mailmanmulti/0013.txthttp://rhn.redhat.com/errata/RHSA-2006-0600.htmlhttp://secunia.com/advisories/21732http://secunia.com/advisories/21792http://secunia.com/advisories/21879http://secunia.com/advisories/22011http://secunia.com/advisories/22020http://secunia.com/advisories/22227http://secunia.com/advisories/22639http://security.gentoo.org/glsa/glsa-200609-12.xmlhttp://securitytracker.com/id?1016808http://sourceforge.net/project/shownotes.php?group_id=103&release_id=444295http://www.debian.org/security/2006/dsa-1188http://www.mandriva.com/security/advisories?name=MDKSA-2006:165http://www.novell.com/linux/security/advisories/2006_25_sr.htmlhttp://www.securityfocus.com/archive/1/445992/100/0/threadedhttp://www.securityfocus.com/bid/19831http://www.securityfocus.com/bid/20021http://www.ubuntu.com/usn/usn-345-1http://www.vupen.com/english/advisories/2006/3446https://exchange.xforce.ibmcloud.com/vulnerabilities/28731https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10553
2006-09-06
Published