Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

GNU Mailman Pipermail Index Summary HTML Injection Vulnerability

HTML tags are not properly filtered from the HTML list archive index. This may enable a remote attacker to inject arbitrary HTML, including script code, into the HTML list archive index.

When a web user views the list index archive containing attacker-supplied script code, the script code will be executed in their web client in the security context of the website running GNU Mailman.







 

Privacy Statement
Copyright 2008, SecurityFocus