CVE-2019-15501
38Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 8.2%
exploitation probability
8.2%top 6% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/47302unverifiedcve_referencepacketstormsecurity.com/files/154202/LSoft-ListServ-Cross-Site-Scripting.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.