First published: Thu Jan 15 2004(Updated: )
Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Mailman | <=2.1.3 | |
Mailman | <=2.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2003-0992 is considered high due to its ability to exploit cross-site scripting vulnerabilities.
To fix CVE-2003-0992, upgrade Mailman to version 2.1.4 or later.
CVE-2003-0992 affects Mailman versions prior to 2.1.3.
Yes, CVE-2003-0992 can be exploited remotely by attackers who send malicious data via the create CGI script.
CVE-2003-0992 allows attackers to steal cookies of other users, leading to potential account compromise.