Show filters
54 Total Results
Displaying 41-50 of 54
Sort by:
Attacker Value
Unknown

CVE-2003-0038

Disclosure Date: February 07, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.
0
Attacker Value
Unknown

CVE-2002-0855

Disclosure Date: September 05, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.
0
Attacker Value
Unknown

CVE-2002-0417

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the ALTERNATE_TEMPLATES parameter for various mmstdo*.cgi programs.
0
Attacker Value
Unknown

CVE-2002-0389

Disclosure Date: June 18, 2002 (last updated February 22, 2025)
Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives.
0
Attacker Value
Unknown

CVE-2002-0388

Disclosure Date: June 18, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries.
0
Attacker Value
Unknown

CVE-2002-0278

Disclosure Date: May 31, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in Add2it Mailman Free 1.73 and earlier allows remote attackers to modify arbitrary files via a .. (dot dot) in the list parameter.
0
Attacker Value
Unknown

CVE-2002-0277

Disclosure Date: May 31, 2002 (last updated February 22, 2025)
Add2it Mailman Free 1.73 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the list parameter.
0
Attacker Value
Unknown

CVE-2001-0884

Disclosure Date: December 21, 2001 (last updated February 22, 2025)
Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.
0
Attacker Value
Unknown

CVE-2001-1132

Disclosure Date: September 05, 2001 (last updated February 22, 2025)
Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication.
0
Attacker Value
Unknown

CVE-2001-0290

Disclosure Date: May 03, 2001 (last updated February 22, 2025)
Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.
0