Page 6 of 29 results (0.010 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el scritp de creación de CGI en Mailman anteriores a 2.1.3 permite a atacantes remotos robar cookies de otros usuarios. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000842 http://mail.python.org/pipermail/mailman-announce/2003-September/000061.html http://www.mandriva.com/security/advisories?name=MDKSA-2004:013 http://www.redhat.com/support/errata/RHSA-2004-020.html https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A815 https://access.redhat.com/security/cve/CVE-2003-0992 https://bugzilla.redhat.com/show_bug.cgi?id=1617120 •

CVSS: 7.5EPSS: 1%CPEs: 1EXPL: 1

Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries. • https://www.exploit-db.com/exploits/21480 http://mail.python.org/pipermail/mailman-announce/2002-May/000042.html http://www.securityfocus.com/bid/4826 https://access.redhat.com/security/cve/CVE-2002-0388 https://bugzilla.redhat.com/show_bug.cgi?id=1616770 •

CVSS: 7.5EPSS: 1%CPEs: 1EXPL: 0

Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000420 http://www.osvdb.org/5455 https://exchange.xforce.ibmcloud.com/vulnerabilities/7091 •

CVSS: 4.6EPSS: 0%CPEs: 1EXPL: 0

Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords. • http://archives.neohapsis.com/archives/bugtraq/2001-03/0031.html •