Show filters
54 Total Results
Displaying 41-50 of 54
Sort by:
Attacker Value
Unknown
CVE-2003-0038
Disclosure Date: February 07, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.
0
Attacker Value
Unknown
CVE-2002-0855
Disclosure Date: September 05, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.
0
Attacker Value
Unknown
CVE-2002-0417
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the ALTERNATE_TEMPLATES parameter for various mmstdo*.cgi programs.
0
Attacker Value
Unknown
CVE-2002-0389
Disclosure Date: June 18, 2002 (last updated February 22, 2025)
Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives.
0
Attacker Value
Unknown
CVE-2002-0388
Disclosure Date: June 18, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries.
0
Attacker Value
Unknown
CVE-2002-0278
Disclosure Date: May 31, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in Add2it Mailman Free 1.73 and earlier allows remote attackers to modify arbitrary files via a .. (dot dot) in the list parameter.
0
Attacker Value
Unknown
CVE-2002-0277
Disclosure Date: May 31, 2002 (last updated February 22, 2025)
Add2it Mailman Free 1.73 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the list parameter.
0
Attacker Value
Unknown
CVE-2001-0884
Disclosure Date: December 21, 2001 (last updated February 22, 2025)
Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.
0
Attacker Value
Unknown
CVE-2001-1132
Disclosure Date: September 05, 2001 (last updated February 22, 2025)
Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication.
0
Attacker Value
Unknown
CVE-2001-0290
Disclosure Date: May 03, 2001 (last updated February 22, 2025)
Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.
0