Description
In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.
Remediation
References
Related Vulnerabilities
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-3946)
WordPress Plugin IQ Testimonials Arbitrary File Upload (2.2.7)
WordPress Plugin RSS Includes Pages Unspecified Vulnerability (3.1)
WordPress Plugin Survey Maker-Best WordPress Survey Cross-Site Scripting (2.0.6)