漏洞信息详情
GNU Mailman订阅跨站脚本漏洞
- CNNVD编号:CNNVD-200209-011
- 危害等级: 高危
- CVE编号:
CVE-2002-0855
- 漏洞类型:
跨站脚本
- 发布时间:
2002-09-05
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
gnu - 漏洞来源:
Discovery of this … -
漏洞简介
Mailman 2.0.12之前的版本存在跨站脚本漏洞。远程攻击者作为其他用户借助ml-name功能中(1)adminpw或者(2)info参数用户的订阅选项单执行脚本。
漏洞公告
This issue has been address in Mailman version 2.0.12.
GNU Mailman 2.0
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.1
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.10
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.11
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.2
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.3
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.4
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.5
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.6
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.7
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
GNU Mailman 2.0.8
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz -
Red Hat mailman-2.0.13-1.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/mailman-2.0.13-1.i386.rpm -
Red Hat mailman-2.0.13-1.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/mailman-2.0.13-1.i386.rpm -
Red Hat mailman-2.0.13-1.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/mailman-2.0.13-1.ia64.rpm
GNU Mailman 2.0.9
-
GNU mailman-2.0.12.tgz
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.12.tgz
参考网址
来源: BID
名称: 5298
链接:http://www.securityfocus.com/bid/5298
来源: mail.python.org
链接:http://mail.python.org/pipermail/mailman-announce/2002-July/000043.html
来源: REDHAT
名称: RHSA-2002:181
链接:http://www.redhat.com/support/errata/RHSA-2002-181.html
来源: REDHAT
名称: RHSA-2002:178
链接:http://www.redhat.com/support/errata/RHSA-2002-178.html
来源: REDHAT
名称: RHSA-2002:177
链接:http://www.redhat.com/support/errata/RHSA-2002-177.html
来源: REDHAT
名称: RHSA-2002:176
链接:http://www.redhat.com/support/errata/RHSA-2002-176.html
来源: XF
名称: mailman-subscription-option-xss(9985)
链接:http://www.iss.net/security_center/static/9985.php
来源: DEBIAN
名称: DSA-147
链接:http://www.debian.org/security/2002/dsa-147
来源: BUGTRAQ
名称: 20020724 cross-site scripting bug of Mailman
链接:http://archives.neohapsis.com/archives/bugtraq/2002-07/0268.html
来源: CONECTIVA
名称: CLA-2002:522
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000522