CVE-2008-0564
published 2008-02-05CVE-2008-0564: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.92%
77.7th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) editing templates and (2) the list's "info attribute" in the web administrator interface, a different vulnerability than CVE-2006-3636.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | >= 0 < 1:2.1.10~b3-1 | 1:2.1.10~b3-1 |
| mailman | mailman | <= 2.1.10b | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qrw2-cc7v-xx92: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2
ghsa_unreviewed·2022-05-01·CVSS 6.8
CVE-2008-0564 [MEDIUM] CWE-79 GHSA-qrw2-cc7v-xx92: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) editing templates and (2) the list's "info attribute" in the web administrator interface, a different vulnerability than CVE-2006-3636.
OSV
CVE-2008-0564: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2
osv·2008-02-05·CVSS 6.8
CVE-2008-0564 [MEDIUM] CVE-2008-0564: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) editing templates and (2) the list's "info attribute" in the web administrator interface, a different vulnerability than CVE-2006-3636.
Ubuntu
mailman vulnerability
vendor_ubuntu·2008-03-15
CVE-2008-0564 mailman vulnerability
Title: mailman vulnerability
Summary: mailman vulnerability
Multiple cross-site scripting flaws were discovered in mailman.
A malicious list administrator could exploit this to execute arbitrary
JavaScript, potentially stealing user credentials.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
NOTE: Due to an internal release testing mistake, earlier
published mailman versions 1:2.1.9-4ubuntu1.1 (for Ubuntu
7.04) and 1:2.1.9-8ubuntu0.1 (for Ubuntu 7.10) accidentally
included an incorrect patch and caused a regression, as reported in
https://launchpad.net/bugs/202332
This update includes fixes for the problem. We apologize for the
inconvenience.
Red Hat
mailman: XSS triggerable by list administrator
vendor_redhat·2008-01-03·CVSS 6.8
CVE-2008-0564 [MEDIUM] CWE-79 mailman: XSS triggerable by list administrator
mailman: XSS triggerable by list administrator
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) editing templates and (2) the list's "info attribute" in the web administrator interface, a different vulnerability than CVE-2006-3636.
Package: mailman (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlhttp://mail.python.org/pipermail/mailman-announce/2008-February/000096.htmlhttp://secunia.com/advisories/28794http://secunia.com/advisories/28916http://secunia.com/advisories/28966http://secunia.com/advisories/29249http://secunia.com/advisories/29388http://secunia.com/advisories/31687http://secunia.com/advisories/43549http://sourceforge.net/project/shownotes.php?release_id=559308&group_id=103http://support.apple.com/kb/HT4077http://wiki.rpath.com/Advisories:rPSA-2008-0056http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:061http://www.redhat.com/support/errata/RHSA-2011-0307.htmlhttp://www.securityfocus.com/archive/1/488236/100/0/threadedhttp://www.securityfocus.com/bid/27630http://www.ubuntu.com/usn/usn-586-1http://www.vupen.com/english/advisories/2008/0422http://www.vupen.com/english/advisories/2011/0542https://bugzilla.redhat.com/show_bug.cgi?id=431526https://issues.rpath.com/browse/RPL-2207https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00452.htmlhttp://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlhttp://mail.python.org/pipermail/mailman-announce/2008-February/000096.htmlhttp://secunia.com/advisories/28794http://secunia.com/advisories/28916http://secunia.com/advisories/28966http://secunia.com/advisories/29249http://secunia.com/advisories/29388http://secunia.com/advisories/31687http://secunia.com/advisories/43549http://sourceforge.net/project/shownotes.php?release_id=559308&group_id=103http://support.apple.com/kb/HT4077http://wiki.rpath.com/Advisories:rPSA-2008-0056http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:061http://www.redhat.com/support/errata/RHSA-2011-0307.htmlhttp://www.securityfocus.com/archive/1/488236/100/0/threadedhttp://www.securityfocus.com/bid/27630http://www.ubuntu.com/usn/usn-586-1http://www.vupen.com/english/advisories/2008/0422http://www.vupen.com/english/advisories/2011/0542https://bugzilla.redhat.com/show_bug.cgi?id=431526https://issues.rpath.com/browse/RPL-2207https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00452.html
2008-02-05
Published