vendor:
Listserv
by:
SecurityFocus
7.5
CVSS
HIGH
Cross-site scripting
79
CWE
Product Name: Listserv
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Multiple cross-site scripting vulnerabilities in L-Soft Listserv
Multiple cross-site scripting vulnerabilities have been reported in L-Soft Listserv. An attacker may exploit these issues by embedding hostile HTML and script code in a link to a site hosting the software. This could permit theft of cookie-based authentication credentials or other attacks. These issues could also provide an attack vector for latent vulnerabilities in web browser software.
Mitigation:
Ensure that user-supplied input is properly sanitized before being used in the generation of web pages.