Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2005:015: mailman Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the mailman package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2005:015 (mailman).
Florian Weimer discovered a vulnerability in Mailman, which can be exploited by
malicious people to conduct cross-site scripting attacks.
Input is not properly sanitised by 'scripts/driver' when returning error pages.
This can be exploited to execute arbitrary HTML or script code in a user's
browser session in context of a vulnerable site by tricking a user into
visiting a malicious web site or follow a specially crafted link.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:015
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.