Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) the list information field or (2) the list description field.
References
Link Providers
http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052297.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052312.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-updates/2011-05/msg00000.html cve-icon cve-icon
http://mail.python.org/pipermail/mailman-announce/2010-September/000150.html cve-icon cve-icon
http://mail.python.org/pipermail/mailman-announce/2010-September/000151.html cve-icon cve-icon
http://marc.info/?l=oss-security&m=128438736513097&w=2 cve-icon cve-icon
http://marc.info/?l=oss-security&m=128440851513718&w=2 cve-icon cve-icon
http://marc.info/?l=oss-security&m=128441135117819&w=2 cve-icon cve-icon
http://marc.info/?l=oss-security&m=128441237618793&w=2 cve-icon cve-icon
http://marc.info/?l=oss-security&m=128441369020123&w=2 cve-icon cve-icon
http://secunia.com/advisories/41265 cve-icon cve-icon
http://secunia.com/advisories/42502 cve-icon cve-icon
http://secunia.com/advisories/43294 cve-icon cve-icon
http://secunia.com/advisories/43425 cve-icon cve-icon
http://secunia.com/advisories/43549 cve-icon cve-icon
http://secunia.com/advisories/43580 cve-icon cve-icon
http://support.apple.com/kb/HT4581 cve-icon cve-icon
http://www.debian.org/security/2011/dsa-2170 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2011-0307.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2011-0308.html cve-icon cve-icon
http://www.ubuntu.com/usn/USN-1069-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/3271 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0436 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0460 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0542 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=631859 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=631881 cve-icon cve-icon
https://launchpad.net/mailman/+milestone/2.1.14rc1 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2010-3089 cve-icon
https://www.cve.org/CVERecord?id=CVE-2010-3089 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2010-09-15T19:00:00

Updated: 2024-08-07T02:55:46.792Z

Reserved: 2010-08-20T00:00:00

Link: CVE-2010-3089

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-09-15T20:00:02.103

Modified: 2023-02-13T04:22:28.927

Link: CVE-2010-3089

cve-icon Redhat

Severity : Low

Publid Date: 2010-09-09T00:00:00Z

Links: CVE-2010-3089 - Bugzilla