CVE-2003-0992: XSS
Published Jan 15, 2004
·Updated
Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.
Affected Software
1 affected component
GNU Mailman<=2.1.3
Remediation
Patch Available
Event History
Jan 15, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-0992?
The severity of CVE-2003-0992 is considered high due to its ability to exploit cross-site scripting vulnerabilities.
2
How do I fix CVE-2003-0992?
To fix CVE-2003-0992, upgrade Mailman to version 2.1.4 or later.
3
What systems are affected by CVE-2003-0992?
CVE-2003-0992 affects Mailman versions prior to 2.1.3.
4
Can CVE-2003-0992 be exploited remotely?
Yes, CVE-2003-0992 can be exploited remotely by attackers who send malicious data via the create CGI script.
5
What impact does CVE-2003-0992 have on users?
CVE-2003-0992 allows attackers to steal cookies of other users, leading to potential account compromise.