[Mailman-Users] MM admin interface wide open

Ulf Hofemeier ulf at ladb.unm.edu
Tue Aug 25 22:31:49 CEST 2009


I'm using MM 2.1.12 and am running into a problem that is rather nasty.
In my case the MM admin interface is wide open, which means that I don't
need a site admin pwd to access http://mydomain/mailman/admin/mylist. I
can click on logout and it will take me to the logout page, but simply
removing /logout from the URL will load the admin interface again.
Deleting the cookie doesn't help, closing the browser doesn't help. Oh,
yeah. The admin interface is accessible via Google as well.

*hysteric scream* HELP please! ;-)

PS. if you email me, I can provide you with the URL to my MM installation.


Ulf Hofemeier
Programmer / Analyst II
Latin American and Iberian Institute
ulf at ladb.unm.edu 

More information about the Mailman-Users mailing list