CVE-2002-0855 describes a cross-site scripting (XSS) vulnerability in GNU Mailman versions prior to 2.0.12. This flaw allows remote attackers to execute arbitrary script in a user's browser by injecting malicious code into a subscriber's list subscription options, specifically through the adminpw or info parameters of the ml-name feature. With a CVSS score of 7.5, this vulnerability is considered highly severe due to its low attack complexity and potential for unauthorized access to sensitive information (C:P), integrity compromise (I:P), and denial of service (A:P). While not listed on the KEV catalog, exploit code is publicly available on ExploitDB, indicating a clear path for exploitation, though there is minimal community discussion or media coverage surrounding this older vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.12CPE matchmatch criteria | cpe:2.3:a:gnu:mailman:2.0.12:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.