Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Mailman | 2.1 |
References
- http://mail.python.org/pipermail/mailman-announce/2006-September/000087.html
- http://moritz-naumann.com/adv/0013/mailmanmulti/0013.txt
- http://rhn.redhat.com/errata/RHSA-2006-0600.html
- http://secunia.com/advisories/21732PatchVendor Advisory
- http://secunia.com/advisories/21792
- http://secunia.com/advisories/21879
- http://secunia.com/advisories/22011
- http://secunia.com/advisories/22020
- http://secunia.com/advisories/22227
- http://secunia.com/advisories/22639
- http://security.gentoo.org/glsa/glsa-200609-12.xml
- http://securitytracker.com/id?1016808
- http://sourceforge.net/project/shownotes.php?group_id=103&release_id=444295Patch
- http://www.debian.org/security/2006/dsa-1188
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:165
FAQ
What is CVE-2006-3636?
CVE-2006-3636 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
How severe is CVE-2006-3636?
CVE-2006-3636 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-3636?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Mailman.