8769911 2002-07-24 17:03 +0900  /68 rader/ office <office@office.ac>
Sänt av: joel@lysator.liu.se
Importerad: 2002-07-24  20:42  av Brevbäraren
Extern mottagare: bugtraq@securityfocus.com
Extern kopiemottagare: office@ukky.net
Mottagare: Bugtraq (import) <23213>
Ärende: cross-site scripting bug of Mailman
From: office <office@office.ac>
To: bugtraq@securityfocus.com
Cc: office@ukky.net
Message-ID: <20020724165024.109C.OFFICE@office.ac>

Mailman: cross-site scripting bug

Product: Mailman
Affected Version: 2.0.11 and under it
Vendor's URL: http://www.gnu.org/software/mailman/
Solution: Use fixed version 2.0.12 or later

Mailman is software to help manage electronic mail discussion lists, much 
like Majordomo or Smartmail. And Mailman have web interface system.

This is simple example for version 2.0.10:
You can recognize the vulnerability with this type of URL;
and that prove that any (malicious) script code is possible on web 
interface part of Mailman.

For example, if you access to this URL with Internet Explorer (other
browser is not affected by the URL), the page figure is similar to
real one, but the password of admin you enter and submit are send  to
another malicious site (http://www.office.ac/). This URL are valid
for version 2.0.10.


And Mailman 2.0.11 still have vulnerabilities, if you access to these 
URL with Internet Explorer (other browser is not affected by these 
URL), your information in cookie about the mailman_site could be 
send another malicious site (http://www.office.ac/).



Vendor's response:
The vendor were notified about first problem on 20th of May 2002. 
On same 20th May 2002, version 2.0.11 was released.

And the vendor were notified about other problems on 21st of May
2002.  The fixed version 2.0.12 was released on 11th of Jul 2002.

Users should upgrade to Mailman 2.0.12 or later

(8769911) /office <office@office.ac>/-----(Ombruten)