First published: Thu Jan 15 2004(Updated: )
Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Mailman | <=2.1.4 | |
Mailman | <=2.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0965 is considered a medium severity vulnerability due to its potential for session cookie theft and unauthorized actions.
To fix CVE-2003-0965, upgrade to Mailman version 2.1.4 or later, as this version contains the fix for the vulnerability.
CVE-2003-0965 affects users of Mailman versions prior to 2.1.4, specifically those using the admin CGI script.
CVE-2003-0965 allows attackers to conduct cross-site scripting (XSS) attacks, which can lead to session cookie theft.
There are no recorded effective workarounds for CVE-2003-0965; upgrading to a secure version is the recommended action.