CVE-2006-1712: XSS
Published Apr 11, 2006
·Updated
Cross-site scripting (XSS) vulnerability in the private archive script (private.py) in GNU Mailman 2.1.7 allows remote attackers to inject arbitrary web script or HTML via the action argument.
Affected Software
1 affected component
GNU Mailman=2.1.7
Remediation
Patch Available
Patch Available
Patch Available
Event History
Apr 11, 2006
CVE Published
07:06 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1712?
CVE-2006-1712 is classified as a high severity vulnerability due to its ability to allow cross-site scripting attacks.
2
How do I fix CVE-2006-1712?
To fix CVE-2006-1712, it is recommended to upgrade GNU Mailman to a version newer than 2.1.7, which addresses the vulnerability.
3
What type of vulnerability is CVE-2006-1712?
CVE-2006-1712 is a cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2006-1712?
All users of GNU Mailman version 2.1.7 are affected by CVE-2006-1712.
5
Can CVE-2006-1712 be exploited remotely?
Yes, CVE-2006-1712 can be exploited remotely by attackers who can inject arbitrary web scripts or HTML.