CVE-2003-0965: XSS
Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0965?
CVE-2003-0965 is considered a medium severity vulnerability due to its potential for session cookie theft and unauthorized actions.
How do I fix CVE-2003-0965?
To fix CVE-2003-0965, upgrade to Mailman version 2.1.4 or later, as this version contains the fix for the vulnerability.
Who is affected by CVE-2003-0965?
CVE-2003-0965 affects users of Mailman versions prior to 2.1.4, specifically those using the admin CGI script.
What kind of attack is possible with CVE-2003-0965?
CVE-2003-0965 allows attackers to conduct cross-site scripting (XSS) attacks, which can lead to session cookie theft.
Is there any workaround for CVE-2003-0965?
There are no recorded effective workarounds for CVE-2003-0965; upgrading to a secure version is the recommended action.