Vulnerability Description
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Mailman | 2.1 |
References
- http://marc.info/?l=bugtraq&m=104342745916111
- http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txtPatch
- http://www.debian.org/security/2004/dsa-436PatchVendor Advisory
- http://www.osvdb.org/9205
- http://www.securityfocus.com/bid/6677
- http://www.securitytracker.com/id?1005987
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11152
- http://marc.info/?l=bugtraq&m=104342745916111
- http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txtPatch
- http://www.debian.org/security/2004/dsa-436PatchVendor Advisory
- http://www.osvdb.org/9205
- http://www.securityfocus.com/bid/6677
- http://www.securitytracker.com/id?1005987
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11152
FAQ
What is CVE-2003-0038?
CVE-2003-0038 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.
How severe is CVE-2003-0038?
CVE-2003-0038 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0038?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Mailman.