CVE-2002-0855 – GNU Mailman 2.0.x - Admin Login Variant Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2002-0855
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature. Vulnerabilidad de secuencias de comandos en sitios cruzados en Mailman 2.0.12 permite a atacantes remotos la ejecución de rutinas como otro usuario mediante las opciones de subscripción de la lista de subscriptores. • https://www.exploit-db.com/exploits/21642 https://www.exploit-db.com/exploits/21641 http://archives.neohapsis.com/archives/bugtraq/2002-07/0268.html http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000522 http://mail.python.org/pipermail/mailman-announce/2002-July/000043.html http://www.debian.org/security/2002/dsa-147 http://www.iss.net/security_center/static/9985.php http://www.redhat.com/support/errata/RHSA-2002-176.html http://www.redhat.com/support/errata •
CVE-2002-0388 – GNU Mailman 2.0.x - Admin Login Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2002-0388
Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries. • https://www.exploit-db.com/exploits/21480 http://mail.python.org/pipermail/mailman-announce/2002-May/000042.html http://www.securityfocus.com/bid/4826 https://access.redhat.com/security/cve/CVE-2002-0388 https://bugzilla.redhat.com/show_bug.cgi?id=1616770 •
CVE-2001-1132
https://notcve.org/view.php?id=CVE-2001-1132
Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000420 http://www.osvdb.org/5455 https://exchange.xforce.ibmcloud.com/vulnerabilities/7091 •
CVE-2001-0290
https://notcve.org/view.php?id=CVE-2001-0290
Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords. • http://archives.neohapsis.com/archives/bugtraq/2001-03/0031.html •
CVE-2000-0861
https://notcve.org/view.php?id=CVE-2000-0861
Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion. • http://archives.neohapsis.com/archives/bugtraq/2000-09/0040.html http://archives.neohapsis.com/archives/freebsd/2000-09/0112.html http://www.securityfocus.com/bid/1667 https://exchange.xforce.ibmcloud.com/vulnerabilities/5493 •