CVE-2006-1712
Cross-site scripting (XSS) vulnerability in the private archive script (private.py) in GNU Mailman 2.1.7 allows remote attackers to inject arbitrary web script or HTML via the action argument.
Date published : 2006-04-11
http://www.securityfocus.com/bid/17403
http://www.mail-archive.com/mailman-checkins@python.org/msg06273.html