Description
Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-2460 Vulnerability (CVE-2013-2460)
e107 Other Vulnerability (CVE-2005-3594)
Artifactory Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10324)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2019-17571)
WordPress Plugin YouTube Cross-Site Request Forgery (11.8.1)