First published: Tue Apr 11 2006(Updated: )
Cross-site scripting (XSS) vulnerability in the private archive script (private.py) in GNU Mailman 2.1.7 allows remote attackers to inject arbitrary web script or HTML via the action argument.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Mailman | =2.1.7 | |
Mailman | =2.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1712 is classified as a high severity vulnerability due to its ability to allow cross-site scripting attacks.
To fix CVE-2006-1712, it is recommended to upgrade GNU Mailman to a version newer than 2.1.7, which addresses the vulnerability.
CVE-2006-1712 is a cross-site scripting (XSS) vulnerability.
All users of GNU Mailman version 2.1.7 are affected by CVE-2006-1712.
Yes, CVE-2006-1712 can be exploited remotely by attackers who can inject arbitrary web scripts or HTML.