Short Name |
HTTP:XSS:MAILMAN-ADMIN |
---|---|
Severity |
Low |
Recommended |
No |
Category |
HTTP |
Keywords |
Mailman Admin Interface Cross-Site Scripting |
Release Date |
2005/01/19 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a cross-site scripting vulnerability in the Mailman administrative Web interface.
Multiple cross-site scripting vulnerabilities were reported to exist in the administrative pages for GNU Mailman. These issues would likely be exploitable by enticing an administrative user to follow a malicious link with hostile HTML and script code embedded in it. Exploitation would likely result in theft of administrative cookie-based authentication credentials. Other attacks would also be possible.