3.5

CVE-2010-3089

Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) the list information field or (2) the list description field.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gnu ≫ Mailman Version <= 2.1.13
Gnu ≫ Mailman Version 2.1
Gnu ≫ Mailman Version 2.1 Update alpha
Gnu ≫ Mailman Version 2.1 Update beta
Gnu ≫ Mailman Version 2.1 Update stable
Gnu ≫ Mailman Version 2.1.1
Gnu ≫ Mailman Version 2.1.2
Gnu ≫ Mailman Version 2.1.3
Gnu ≫ Mailman Version 2.1.4
Gnu ≫ Mailman Version 2.1.5
Gnu ≫ Mailman Version 2.1.6
Gnu ≫ Mailman Version 2.1.7
Gnu ≫ Mailman Version 2.1.8
Gnu ≫ Mailman Version 2.1.9
Gnu ≫ Mailman Version 2.1.10
Gnu ≫ Mailman Version 2.1.11
Gnu ≫ Mailman Version 2.1.11 Update rc1
Gnu ≫ Mailman Version 2.1.11 Update rc2
Gnu ≫ Mailman Version 2.1.12
Gnu ≫ Mailman Version 2.1.13 Update rc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.97% 0.779
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://secunia.com/advisories/43549
http://www.redhat.com/support/errata/RHSA-2011-0307.html
http://www.vupen.com/english/advisories/2011/0542
http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html
http://support.apple.com/kb/HT4581
http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052297.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052312.html
http://lists.opensuse.org/opensuse-updates/2011-05/msg00000.html
http://mail.python.org/pipermail/mailman-announce/2010-September/000150.html
http://mail.python.org/pipermail/mailman-announce/2010-September/000151.html
http://marc.info/?l=oss-security&m=128438736513097&w=2
http://marc.info/?l=oss-security&m=128440851513718&w=2
http://marc.info/?l=oss-security&m=128441135117819&w=2
http://marc.info/?l=oss-security&m=128441237618793&w=2
http://marc.info/?l=oss-security&m=128441369020123&w=2
http://secunia.com/advisories/41265
Vendor Advisory
http://secunia.com/advisories/42502
http://secunia.com/advisories/43294
http://secunia.com/advisories/43425
http://secunia.com/advisories/43580
http://www.debian.org/security/2011/dsa-2170
http://www.redhat.com/support/errata/RHSA-2011-0308.html
http://www.ubuntu.com/usn/USN-1069-1
http://www.vupen.com/english/advisories/2010/3271
http://www.vupen.com/english/advisories/2011/0436
http://www.vupen.com/english/advisories/2011/0460
https://bugzilla.redhat.com/show_bug.cgi?id=631859
https://bugzilla.redhat.com/show_bug.cgi?id=631881
https://launchpad.net/mailman/+milestone/2.1.14rc1