Show filters
54 Total Results
Displaying 21-30 of 54
Sort by:
Attacker Value
Unknown
CVE-2009-2164
Disclosure Date: June 22, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the code parameter to activate.php or (2) the dest parameter to index.php.
0
Attacker Value
Unknown
CVE-2008-0564
Disclosure Date: February 05, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) editing templates and (2) the list's "info attribute" in the web administrator interface, a different vulnerability than CVE-2006-3636.
0
Attacker Value
Unknown
CVE-2006-2191
Disclosure Date: September 19, 2006 (last updated November 08, 2023)
Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via unspecified vectors. NOTE: the vendor has disputed this vulnerability, stating that it is "unexploitable.
0
Attacker Value
Unknown
CVE-2006-4624
Disclosure Date: September 07, 2006 (last updated October 04, 2023)
CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.
0
Attacker Value
Unknown
CVE-2006-2941
Disclosure Date: September 06, 2006 (last updated October 04, 2023)
Mailman before 2.1.9rc1 allows remote attackers to cause a denial of service via unspecified vectors involving "standards-breaking RFC 2231 formatted headers".
0
Attacker Value
Unknown
CVE-2006-3636
Disclosure Date: September 06, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2006-2824
Disclosure Date: June 05, 2006 (last updated October 04, 2023)
Logicalware MailManager before 2.0.10 does not remove 0xc8 0x27 (0xc8 followed by a single-quote character) from the data stream to the server, which allows remote attackers to modify data and gain administrative access when PostgreSQL is used, aka "bug #1494281 - Postgres encoding security hole." NOTE: while this issue involves PostgreSQL, it is specific to MailManager's interface to PostgreSQL and is therefore a different vulnerability than CVE-2006-2313 and CVE-2006-2314.
0
Attacker Value
Unknown
CVE-2006-1712
Disclosure Date: April 11, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the private archive script (private.py) in GNU Mailman 2.1.7 allows remote attackers to inject arbitrary web script or HTML via the action argument.
0
Attacker Value
Unknown
CVE-2006-0052
Disclosure Date: March 31, 2006 (last updated February 22, 2025)
The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.
0
Attacker Value
Unknown
CVE-2005-4153
Disclosure Date: December 11, 2005 (last updated February 22, 2025)
Mailman 2.1.4 through 2.1.6 allows remote attackers to cause a denial of service via a message that causes the server to "fail with an Overflow on bad date data in a processed message," a different vulnerability than CVE-2005-3573.
0