Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.50933
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDKSA-2005:015 (mailman)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to mailman
announced via advisory MDKSA-2005:015.

Florian Weimer discovered a vulnerability in Mailman, which can be
exploited by malicious people to conduct cross-site scripting attacks.

Input is not properly sanitised by scripts/driver when returning error
pages. This can be exploited to execute arbitrary HTML or script code in
a user's browser session in context of a vulnerable site by tricking a user
into visiting a malicious web site or follow a specially crafted link.
(CVE-2004-1177).

Affected versions: 10.0, 10.1, Corporate Server 2.1,
Corporate Server 3.0


Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDKSA-2005:015
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1177

Risk factor : Medium

CVSS Score:
4.3

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2004-1177
Bugtraq: 20050110 [USN-59-1] mailman vulnerabilities (Google Search)
http://marc.info/?l=bugtraq&m=110549296126351&w=2
Debian Security Information: DSA-674 (Google Search)
http://www.debian.org/security/2005/dsa-674
http://www.mandriva.com/security/advisories?name=MDKSA-2005:015
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11113
http://www.redhat.com/support/errata/RHSA-2005-235.html
http://secunia.com/advisories/13603
SuSE Security Announcement: SUSE-SA:2005:007 (Google Search)
http://www.novell.com/linux/security/advisories/2005_07_mailman.html
XForce ISS Database: mailman-script-driver-xss(18854)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18854
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.