Vulnerability Name:
CVE-2001-0884 (CCN-7617)
Assigned:
2001-11-28
Published:
2001-11-28
Updated:
2017-10-10
Summary:
Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.
CVSS v3 Severity:
5.6 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
High
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
Low
Integrity (I):
Low
Availibility (A):
Low
CVSS v2 Severity:
5.1 Medium
(CVSS v2 Vector:
AV:N/AC:H/Au:N/C:P/I:P/A:P
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
High
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
Partial
5.1 Medium
(CCN CVSS v2 Vector:
AV:N/AC:H/Au:N/C:P/I:P/A:P
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
High
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
Partial
Vulnerability Type:
CWE-Other
Vulnerability Consequences:
Obtain Information
References:
Source: MITRE
Type: CNA
CVE-2001-0884
Source: CCN
Type: Conectiva Linux Announcement CLSA-2001:445
Mailman Cross-Site Scripting Vulnerability
Source: CCN
Type: RHSA-2001-168
Updated Mailman packages available
Source: CCN
Type: RHSA-2001-169
Updated Mailman packages available
Source: CCN
Type: SourceForge.net
Mailman
Source: CCN
Type: Cgi Security Advisory #7
Mailman Email archiver Cross Site Scripting Hole
Source: DEBIAN
Type: DSA-094
mailman -- cross-site scripting hole
Source: CCN
Type: OSVDB ID: 5531
Mailman listinfo JavaScript XSS
Source: REDHAT
Type: UNKNOWN
RHSA-2001:168
Source: REDHAT
Type: UNKNOWN
RHSA-2001:169
Source: REDHAT
Type: UNKNOWN
RHSA-2001:170
Source: CONECTIVA
Type: Patch, Vendor Advisory
CLA-2001:445
Source: BUGTRAQ
Type: Patch, Vendor Advisory
20011128 Cgisecurity.com Advisory #7: Mailman Email Archive Cross Site Scripting
Source: BID
Type: UNKNOWN
3602
Source: CCN
Type: BID-3602
GNU Mailman Cross-Site Scripting Vulnerability
Source: XF
Type: UNKNOWN
mailman-java-xss(7617)
Source: XF
Type: UNKNOWN
mailman-java-css(7617)
Vulnerable Configuration:
Configuration 1
:
cpe:/a:gnu:mailman:*:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:5.0:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:5.1:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:6.0:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:7.0:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:gnu:mailman:1.0:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:1.1:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0.1:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0.10:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0.11:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0.12:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0.13:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0.14:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0.2:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0.3:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0.4:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0.5:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0.6:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0.7:*:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0:beta3:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0:beta4:*:*:*:*:*:*
OR
cpe:/a:gnu:mailman:2.0:beta5:*:*:*:*:*:*
AND
cpe:/o:debian:debian_linux:2.2:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:7:*:*:*:*:*:*:*
OR
cpe:/o:conectiva:linux:6.0:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:7.1:*:*:*:*:*:*:*
OR
cpe:/o:conectiva:linux:5.0:*:*:*:*:*:*:*
OR
cpe:/o:conectiva:linux:5.1:*:*:*:*:*:*:*
OR
cpe:/o:conectiva:linux:7.0:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:7.2:*:*:*:*:*:*:*
OR
cpe:/a:redhat:linux_powertools:7.0:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:7.3:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
gnu
mailman *
gnu
mailman 5.0
gnu
mailman 5.1
gnu
mailman 6.0
gnu
mailman 7.0
gnu
mailman 1.0
gnu
mailman 1.1
gnu
mailman 2.0
gnu
mailman 2.0.1
gnu
mailman 2.0.10
gnu
mailman 2.0.11
gnu
mailman 2.0.12
gnu
mailman 2.0.13
gnu
mailman 2.0.14
gnu
mailman 2.0.2
gnu
mailman 2.0.3
gnu
mailman 2.0.4
gnu
mailman 2.0.5
gnu
mailman 2.0.6
gnu
mailman 2.0.7
gnu
mailman 2.0 beta3
gnu
mailman 2.0 beta4
gnu
mailman 2.0 beta5
debian
debian linux 2.2
redhat
linux 7
conectiva
linux 6.0
redhat
linux 7.1
conectiva
linux 5.0
conectiva
linux 5.1
conectiva
linux 7.0
redhat
linux 7.2
redhat
linux powertools 7.0
redhat
linux 7.3