CVE-2004-1177: XSS
Published Jan 10, 2005
·Updated
Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.
Affected Software
26 affected componentsFixes available
pip/mailman<2.1.5
2.1.5
GNU Mailman=1.0
GNU Mailman=1.1
GNU Mailman=2.0
GNU Mailman=2.0-beta3
GNU Mailman=2.0-beta4
GNU Mailman=2.0-beta5
GNU Mailman=2.0.1
GNU Mailman=2.0.2
GNU Mailman=2.0.3
GNU Mailman=2.0.4
GNU Mailman=2.0.5
GNU Mailman=2.0.6
GNU Mailman=2.0.7
GNU Mailman=2.0.8
GNU Mailman=2.0.9
GNU Mailman=2.0.10
GNU Mailman=2.0.11
GNU Mailman=2.0.12
GNU Mailman=2.0.13
GNU Mailman=2.1
GNU Mailman=2.1.1
GNU Mailman=2.1.2
GNU Mailman=2.1.3
GNU Mailman=2.1.4
GNU Mailman=2.1b1
Remediation
Patch Available
Patch Available
Event History
Jan 10, 2005
CVE Published
05:00 AM
Jan 19, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Apr 29, 2022
Advisory Published
02:59 AM
Frequently Asked Questions
1
What is the severity of CVE-2004-1177?
CVE-2004-1177 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2004-1177?
To fix CVE-2004-1177, upgrade Mailman to version 2.1.5 or later.
3
What versions are affected by CVE-2004-1177?
CVE-2004-1177 affects Mailman versions prior to 2.1.5, including 2.0.1, 2.0.5, and several other earlier versions.
4
What is the impact of CVE-2004-1177?
The impact of CVE-2004-1177 allows remote attackers to inject arbitrary web scripts or HTML into error pages.
5
Who is primarily affected by CVE-2004-1177?
Websites that use vulnerable versions of the Mailman mailing list software are primarily affected by CVE-2004-1177.