CVE
- Id
- 5245
- CVE No.
- CVE-2002-0855
- Status
- Candidate
- Description
- Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber"s list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.
- Phase
- Modified (20030325-01)
- Votes
- ACCEPT(3) Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(2) Christey, Foat
- Comments
- Cox> ADDREF:REDHAT:RHSA-2002:181 | Frech> XF:mailman-subscription-option-xss(9985) | Christey> Add to desc: "via the (1) adminpw or (2) info parameters to | the ml-name feature. | ADDREF CONECTIVA:CLA-2002:522 | | It"s not clear whether DEBIAN:DSA-147-2 addresses this issue | in addition to, or instead of, CVE-2002-0388 | Christey> BID:5298 | | Debian (Joey) has confirmed that DSA-147 also addresses this | issue.