Published:2005/04/19  Last Updated:2008/05/21

JVN#97757029
w3ml cross-site scripting vulnerability

Overview

w3ml, a program used to display mailing list logs on the web site, contains a cross-site scripting vulnerability.

Products Affected

  • w3ml-0.4-20020625 and earlier

Description

Impact

An arbitrary script could be executed on the user's web browser which may allow an attacker to steal cookie information.

Solution

Vendor Status

Vendor Status Last Update Vendor Notes
TOMITA Masahiro Vulnerable 2005/04/19

References

JPCERT/CC Addendum

Credit

Kiyotaka Doumae of IIJ reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendors under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia JVNDB-2005-000766

Update History