CVE-2011-0707
Publication date 18 February 2011
Last updated 24 July 2024
Ubuntu priority
Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.
Status
Package | Ubuntu Release | Status |
---|---|---|
mailman | ||
Patch details
Package | Patch details |
---|---|
mailman |
References
Related Ubuntu Security Notices (USN)
- USN-1069-1
- Mailman vulnerabilities
- 22 February 2011