Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2006-3636Cross-site Scripting in Mailman

CWE-79Cross-site Scripting15 documents8 sources
Severity
6.8MEDIUMNVD
EPSS
20.4%
top 4.45%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedSep 6
Latest updateMay 1

Description

Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

NVDgnu/mailman11 versions+10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-gh24-6437-cg34: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 22022-05-01
OSV
CVE-2008-0564: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 22008-02-05
CVEList
CVE-2006-3636: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 22006-09-06

💥Exploits & PoCs

1
Exploit-DB
Mailman 2.1.x - Multiple Input Validation Vulnerabilities2006-09-14

📋Vendor Advisories

3
Red Hat
mailman: XSS triggerable by list administrator2008-01-03
Ubuntu
mailman vulnerabilities2006-09-13
Red Hat
security flaw2006-09-04

💬Community

7
Bugzilla
CVE-2006-3636 security flaw2018-08-16
Bugzilla
CVE-2008-0564 mailman: XSS triggerable by list administrator2008-02-05
Bugzilla
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)2006-10-20
Bugzilla
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)2006-10-07
Bugzilla
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)2006-09-15
CVE-2006-3636 — Cross-site Scripting in GNU Mailman | cvebase