GNU Mailman Pipermail Index Summary HTML注入漏洞

漏洞信息详情

GNU Mailman Pipermail Index Summary HTML注入漏洞

漏洞简介

Mailman before 2.0.11版本存在跨站脚本漏洞。远程攻击者借助1)admin登录页面,或者(2)Pipermail索引摘要执行脚本。

漏洞公告

Debian has released an advisory which addresses this issue. See the attached advisory for details on obtaining fixes.
Upgrades are available:
GNU Mailman 2.0.1

GNU Mailman 2.0.10

GNU Mailman 2.0.2

GNU Mailman 2.0.3

GNU Mailman 2.0.4

GNU Mailman 2.0.5

GNU Mailman 2.0.6

GNU Mailman 2.0.7

GNU Mailman 2.0.8

GNU Mailman 2.0.9

参考网址

来源: mail.python.org
链接:http://mail.python.org/pipermail/mailman-announce/2002-May/000042.html

来源: BID
名称: 4826
链接:http://www.securityfocus.com/bid/4826

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享