CVE

Id
5245  
CVE No.
CVE-2002-0855  
Status
Candidate  
Description
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber"s list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.  
Phase
Modified (20030325-01)  
Votes
ACCEPT(3) Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(2) Christey, Foat  
Comments
Cox> ADDREF:REDHAT:RHSA-2002:181 | Frech> XF:mailman-subscription-option-xss(9985) | Christey> Add to desc: "via the (1) adminpw or (2) info parameters to | the ml-name feature. | ADDREF CONECTIVA:CLA-2002:522 | | It"s not clear whether DEBIAN:DSA-147-2 addresses this issue | in addition to, or instead of, CVE-2002-0388 | Christey> BID:5298 | | Debian (Joey) has confirmed that DSA-147 also addresses this | issue.