CVE-2010-3089

CVSS V2 Low 3.5 CVSS V3 None
Description
Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) the list information field or (2) the list description field.
Overview
  • CVE ID
  • CVE-2010-3089
  • Assigner
  • secalert@redhat.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2010-09-15T20:00:02
  • Last Modified Date
  • 2023-02-13T04:22:28
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:gnu:mailman:*:*:*:*:*:*:*:* 1 OR 2.1.13
cpe:2.3:a:gnu:mailman:2.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1:alpha:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1:stable:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1.9:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1.11:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1.11:rc1:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1.11:rc2:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1.12:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:gnu:mailman:2.1.13:rc1:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:S/C:N/I:P/A:N
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • SINGLE
  • Confidentiality Impact
  • NONE
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • NONE
  • Base Score
  • 3.5
  • Severity
  • LOW
  • Exploitability Score
  • 6.8
  • Impact Score
  • 2.9
References
Reference URL Reference Tags
http://marc.info/?l=oss-security&m=128440851513718&w=2
https://bugzilla.redhat.com/show_bug.cgi?id=631859
http://marc.info/?l=oss-security&m=128441369020123&w=2
http://marc.info/?l=oss-security&m=128438736513097&w=2
http://marc.info/?l=oss-security&m=128441135117819&w=2
http://secunia.com/advisories/41265 Vendor Advisory
http://mail.python.org/pipermail/mailman-announce/2010-September/000150.html
https://launchpad.net/mailman/+milestone/2.1.14rc1
http://mail.python.org/pipermail/mailman-announce/2010-September/000151.html
https://bugzilla.redhat.com/show_bug.cgi?id=631881
http://marc.info/?l=oss-security&m=128441237618793&w=2
http://www.vupen.com/english/advisories/2010/3271
http://secunia.com/advisories/42502
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052297.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052312.html
http://www.vupen.com/english/advisories/2011/0436
http://secunia.com/advisories/43294
http://www.debian.org/security/2011/dsa-2170
http://www.ubuntu.com/usn/USN-1069-1
http://www.vupen.com/english/advisories/2011/0460
http://secunia.com/advisories/43425
http://secunia.com/advisories/43580
http://www.vupen.com/english/advisories/2011/0542
http://secunia.com/advisories/43549
http://www.redhat.com/support/errata/RHSA-2011-0308.html
http://www.redhat.com/support/errata/RHSA-2011-0307.html
http://support.apple.com/kb/HT4581
http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
http://lists.opensuse.org/opensuse-updates/2011-05/msg00000.html
History
Created Old Value New Value Data Type Notes
2022-05-10 10:38:01 Added to TrackCVE
2023-02-02 18:02:42 2023-02-02T17:17:46 CVE Modified Date updated
2023-02-02 18:02:43 Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) the list information field or (2) the list description field. CVE-2010-3089 mailman: Multiple security flaws leading to cross-site scripting (XSS) attacks Description updated
2023-02-13 05:03:49 2023-02-13T04:22:28 CVE Modified Date updated
2023-02-13 05:03:49 CVE-2010-3089 mailman: Multiple security flaws leading to cross-site scripting (XSS) attacks Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) the list information field or (2) the list description field. Description updated