Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

GNU Mailman Subscribe Cross-Site Scripting Vulnerability

GNU Mailman is prone to a cross-site scripting vulnerability. Arbitrary HTML and script code are not sanitized from the URI parameters of mailing list subscribe scripts.

An attacker may exploit this issue by creating a malicious link containing arbitrary script code and enticing a web user to visit the link.







 

Privacy Statement
Copyright 2008, SecurityFocus