CVE-2011-0707
published 2011-02-22CVE-2011-0707: Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
4.25%
90.0th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | <= 2.1.14 | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Mailman vulnerabilities
vendor_ubuntu·2011-02-22
CVE-2010-3089 Mailman vulnerabilities
Title: Mailman vulnerabilities
It was discovered that Mailman did not properly sanitize certain fields,
resulting in cross-site scripting (XSS) vulnerabilities. With cross-site
scripting vulnerabilities, if a user were tricked into viewing server
output during a crafted server request, a remote attacker could exploit
this to modify the contents, or steal confidential data, within the same
domain.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Mailman: Three XSS flaws due improper escaping of the full name of the member
vendor_redhat·2011-02-18·CVSS 4.3
CVE-2011-0707 [MEDIUM] CWE-79 Mailman: Three XSS flaws due improper escaping of the full name of the member
Mailman: Three XSS flaws due improper escaping of the full name of the member
Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.
GHSA
GHSA-24m7-q6q4-w3hx: Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm
ghsa_unreviewed·2022-05-17
CVE-2011-0707 [MEDIUM] CWE-79 GHSA-24m7-q6q4-w3hx: Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm
Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0707 Mailman: Three XSS flaws due improper escaping of the full name of the member [fedora-all]
bugzilla·2011-02-23·CVSS 4.3
CVE-2011-0707 [MEDIUM] CVE-2011-0707 Mailman: Three XSS flaws due improper escaping of the full name of the member [fedora-all]
CVE-2011-0707 Mailman: Three XSS flaws due improper escaping of the full name of the member [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=677375
Please not
Bugzilla
CVE-2011-0707 Mailman: Three XSS flaws due improper escaping of the full name of the member
bugzilla·2011-02-14·CVSS 4.3
CVE-2011-0707 [MEDIUM] CVE-2011-0707 Mailman: Three XSS flaws due improper escaping of the full name of the member
CVE-2011-0707 Mailman: Three XSS flaws due improper escaping of the full name of the member
Mailman, the mailing list manager, did not properly sanitize
full name of the mailing list member, in the following confirmation
dialogs:
1), "Confirm unsubscription request" screen,
2), "Confirm change of email address request" screen,
3), "Re-enable mailing list membership" screen.
A remote, authenticated user could use these flaws to conduct
cross-site scripting (XSS) attacks (execute arbitrary HTML or
scripting code) via a specially-crafted full name of the mailing
list member.
References:
[1] http://mail.python.org/pipermail/mailman-announce/2011-February/000157.html
Acknowledgements:
Red Hat would like to thank Mark Sapiro for reporting these flaws.
Discussion:
These issues affect the v
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056363.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056387.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056399.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2011-05/msg00000.htmlhttp://mail.python.org/pipermail/mailman-announce/2011-February/000157.htmlhttp://mail.python.org/pipermail/mailman-announce/2011-February/000158.htmlhttp://osvdb.org/70936http://secunia.com/advisories/43294http://secunia.com/advisories/43389http://secunia.com/advisories/43425http://secunia.com/advisories/43549http://secunia.com/advisories/43580http://secunia.com/advisories/43829http://support.apple.com/kb/HT5002http://www.debian.org/security/2011/dsa-2170http://www.mandriva.com/security/advisories?name=MDVSA-2011:036http://www.redhat.com/support/errata/RHSA-2011-0307.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0308.htmlhttp://www.securityfocus.com/bid/46464http://www.securitytracker.com/id?1025106http://www.ubuntu.com/usn/USN-1069-1http://www.vupen.com/english/advisories/2011/0435http://www.vupen.com/english/advisories/2011/0436http://www.vupen.com/english/advisories/2011/0460http://www.vupen.com/english/advisories/2011/0487http://www.vupen.com/english/advisories/2011/0542http://www.vupen.com/english/advisories/2011/0720https://exchange.xforce.ibmcloud.com/vulnerabilities/65538http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056363.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056387.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056399.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2011-05/msg00000.htmlhttp://mail.python.org/pipermail/mailman-announce/2011-February/000157.htmlhttp://mail.python.org/pipermail/mailman-announce/2011-February/000158.htmlhttp://osvdb.org/70936http://secunia.com/advisories/43294http://secunia.com/advisories/43389http://secunia.com/advisories/43425http://secunia.com/advisories/43549http://secunia.com/advisories/43580http://secunia.com/advisories/43829http://support.apple.com/kb/HT5002http://www.debian.org/security/2011/dsa-2170http://www.mandriva.com/security/advisories?name=MDVSA-2011:036http://www.redhat.com/support/errata/RHSA-2011-0307.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0308.htmlhttp://www.securityfocus.com/bid/46464http://www.securitytracker.com/id?1025106http://www.ubuntu.com/usn/USN-1069-1http://www.vupen.com/english/advisories/2011/0435http://www.vupen.com/english/advisories/2011/0436http://www.vupen.com/english/advisories/2011/0460http://www.vupen.com/english/advisories/2011/0487http://www.vupen.com/english/advisories/2011/0542http://www.vupen.com/english/advisories/2011/0720https://exchange.xforce.ibmcloud.com/vulnerabilities/65538
2011-02-22
Published