Unrated severityNVD Advisory· Published Sep 15, 2010· Updated Apr 29, 2026
CVE-2010-3089
CVE-2010-3089
Description
Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) the list information field or (2) the list description field.
Affected products
20cpe:2.3:a:gnu:mailman:*:*:*:*:*:*:*:*+ 19 more
- cpe:2.3:a:gnu:mailman:*:*:*:*:*:*:*:*range: <=2.1.13
- cpe:2.3:a:gnu:mailman:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.10:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.11:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.11:rc1:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.11:rc2:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.12:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.13:rc1:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.9:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1:alpha:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1:beta:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1:stable:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
30- secunia.com/advisories/41265nvdVendor Advisory
- lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-December/052297.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-December/052312.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlnvd
- lists.opensuse.org/opensuse-updates/2011-05/msg00000.htmlnvd
- mail.python.org/pipermail/mailman-announce/2010-September/000150.htmlnvd
- mail.python.org/pipermail/mailman-announce/2010-September/000151.htmlnvd
- marc.infonvd
- marc.infonvd
- marc.infonvd
- marc.infonvd
- marc.infonvd
- secunia.com/advisories/42502nvd
- secunia.com/advisories/43294nvd
- secunia.com/advisories/43425nvd
- secunia.com/advisories/43549nvd
- secunia.com/advisories/43580nvd
- support.apple.com/kb/HT4581nvd
- www.debian.org/security/2011/dsa-2170nvd
- www.redhat.com/support/errata/RHSA-2011-0307.htmlnvd
- www.redhat.com/support/errata/RHSA-2011-0308.htmlnvd
- www.ubuntu.com/usn/USN-1069-1nvd
- www.vupen.com/english/advisories/2010/3271nvd
- www.vupen.com/english/advisories/2011/0436nvd
- www.vupen.com/english/advisories/2011/0460nvd
- www.vupen.com/english/advisories/2011/0542nvd
- bugzilla.redhat.com/show_bug.cginvd
- bugzilla.redhat.com/show_bug.cginvd
- launchpad.net/mailman/+milestone/2.1.14rc1nvd
News mentions
0No linked articles in our index yet.