CVE

Id
48619  
CVE No.
CVE-2011-0707  
Status
Candidate  
Description
Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.  
Phase
Assigned (20110131)  
Votes
None (candidate not yet proposed)  
Comments