Unrated severityNVD Advisory· Published Feb 22, 2011· Updated Apr 29, 2026
CVE-2011-0707
CVE-2011-0707
Description
Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.
Affected products
45cpe:2.3:a:gnu:mailman:*:*:*:*:*:*:*:*+ 44 more
- cpe:2.3:a:gnu:mailman:*:*:*:*:*:*:*:*range: <=2.1.14
- cpe:2.3:a:gnu:mailman:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.10:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.11:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.11:rc1:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.11:rc2:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.12:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.13:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.13:rc1:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.14:rc1:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.1:beta1:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.5.8:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1.9:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1:alpha:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1b1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1:beta:*:*:*:*:*:*
- cpe:2.3:a:gnu:mailman:2.1:stable:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
30- mail.python.org/pipermail/mailman-announce/2011-February/000158.htmlnvdPatch
- secunia.com/advisories/43294nvdVendor Advisory
- secunia.com/advisories/43389nvdVendor Advisory
- secunia.com/advisories/43425nvdVendor Advisory
- www.vupen.com/english/advisories/2011/0435nvdVendor Advisory
- www.vupen.com/english/advisories/2011/0436nvdVendor Advisory
- www.vupen.com/english/advisories/2011/0460nvdVendor Advisory
- lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2011-March/056363.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2011-March/056387.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2011-March/056399.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlnvd
- lists.opensuse.org/opensuse-updates/2011-05/msg00000.htmlnvd
- mail.python.org/pipermail/mailman-announce/2011-February/000157.htmlnvd
- osvdb.org/70936nvd
- secunia.com/advisories/43549nvd
- secunia.com/advisories/43580nvd
- secunia.com/advisories/43829nvd
- support.apple.com/kb/HT5002nvd
- www.debian.org/security/2011/dsa-2170nvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2011-0307.htmlnvd
- www.redhat.com/support/errata/RHSA-2011-0308.htmlnvd
- www.securityfocus.com/bid/46464nvd
- www.securitytracker.com/idnvd
- www.ubuntu.com/usn/USN-1069-1nvd
- www.vupen.com/english/advisories/2011/0487nvd
- www.vupen.com/english/advisories/2011/0542nvd
- www.vupen.com/english/advisories/2011/0720nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/65538nvd
News mentions
0No linked articles in our index yet.