Vulnerability Name:

CVE-2001-0884 (CCN-7617)

Assigned:2001-11-28
Published:2001-11-28
Updated:2017-10-10
Summary:Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.
CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2001-0884

Source: CCN
Type: Conectiva Linux Announcement CLSA-2001:445
Mailman Cross-Site Scripting Vulnerability

Source: CCN
Type: RHSA-2001-168
Updated Mailman packages available

Source: CCN
Type: RHSA-2001-169
Updated Mailman packages available

Source: CCN
Type: SourceForge.net
Mailman

Source: CCN
Type: Cgi Security Advisory #7
Mailman Email archiver Cross Site Scripting Hole

Source: DEBIAN
Type: DSA-094
mailman -- cross-site scripting hole

Source: CCN
Type: OSVDB ID: 5531
Mailman listinfo JavaScript XSS

Source: REDHAT
Type: UNKNOWN
RHSA-2001:168

Source: REDHAT
Type: UNKNOWN
RHSA-2001:169

Source: REDHAT
Type: UNKNOWN
RHSA-2001:170

Source: CONECTIVA
Type: Patch, Vendor Advisory
CLA-2001:445

Source: BUGTRAQ
Type: Patch, Vendor Advisory
20011128 Cgisecurity.com Advisory #7: Mailman Email Archive Cross Site Scripting

Source: BID
Type: UNKNOWN
3602

Source: CCN
Type: BID-3602
GNU Mailman Cross-Site Scripting Vulnerability

Source: XF
Type: UNKNOWN
mailman-java-xss(7617)

Source: XF
Type: UNKNOWN
mailman-java-css(7617)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnu:mailman:*:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:5.1:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:7.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:gnu:mailman:1.0:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:1.1:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0.10:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0.11:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0.12:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0.13:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0.14:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0:beta3:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0:beta4:*:*:*:*:*:*
  • OR cpe:/a:gnu:mailman:2.0:beta5:*:*:*:*:*:*
  • AND
  • cpe:/o:debian:debian_linux:2.2:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:5.0:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:5.1:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.2:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:linux_powertools:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    gnu mailman *
    gnu mailman 5.0
    gnu mailman 5.1
    gnu mailman 6.0
    gnu mailman 7.0
    gnu mailman 1.0
    gnu mailman 1.1
    gnu mailman 2.0
    gnu mailman 2.0.1
    gnu mailman 2.0.10
    gnu mailman 2.0.11
    gnu mailman 2.0.12
    gnu mailman 2.0.13
    gnu mailman 2.0.14
    gnu mailman 2.0.2
    gnu mailman 2.0.3
    gnu mailman 2.0.4
    gnu mailman 2.0.5
    gnu mailman 2.0.6
    gnu mailman 2.0.7
    gnu mailman 2.0 beta3
    gnu mailman 2.0 beta4
    gnu mailman 2.0 beta5
    debian debian linux 2.2
    redhat linux 7
    conectiva linux 6.0
    redhat linux 7.1
    conectiva linux 5.0
    conectiva linux 5.1
    conectiva linux 7.0
    redhat linux 7.2
    redhat linux powertools 7.0
    redhat linux 7.3