FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

mailman -- Private Archive Script Cross-Site Scripting

Affected packages
ja-mailman < 2.1.8
mailman < 2.1.8
mailman-with-htdig < 2.1.8

Details

VuXML ID 8be2e304-cce6-11da-a3b1-00123ffe8333
Discovery 2006-04-07
Entry 2006-04-16

Secunia reports:

A vulnerability has been reported in Mailman, which can be exploited by malicious people to conduct cross-site scripting attacks.

Unspecified input passed to the private archive script is not properly sanitised before being returned to users. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of a vulnerable site.

References

CVE Name CVE-2006-1712
Message http://mail.python.org/pipermail/mailman-announce/2006-April/000084.html
URL http://secunia.com/advisories/19558/