A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://peach.ease.lsoft.com/scripts/wa-PEACH.exe?A0=LSTSRV-L | vendor advisory |
https://packetstormsecurity.com/2301-exploits/listserv17-xss.txt | third party advisory vdb entry |