CVE-2004-1177

Publication date 10 January 2005

Last updated 24 July 2024


Ubuntu priority

Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.

Status

Package Ubuntu Release Status
mailman 7.04 feisty
Fixed 2.1.8-2ubuntu2
6.10 edgy
Fixed 2.1.8-2ubuntu2
6.06 LTS dapper
Fixed 2.1.5-9ubuntu4.1

References

Related Ubuntu Security Notices (USN)

    • USN-59-1
    • mailman vulnerabilities
    • 11 January 2005

Other references