Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
listmanager vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2014-5188
Cross-site scripting (XSS) vulnerability in doemailpassword.tml in Lyris ListManager (LM) 8.95a allows remote malicious users to inject arbitrary web script or HTML via the EmailAddr parameter.
Lyris List Manager 8.95a
383
VMScore
CVE-2008-2923
Cross-site scripting (XSS) vulnerability in read/search/results in Lyris ListManager 8.8, 8.95, and 9.3d allows remote malicious users to inject arbitrary web script or HTML via the words parameter.
Lyris List Manager 9.3d
Lyris List Manager 8.95
Lyris List Manager 8.8
890
VMScore
CVE-2007-6319
Multiple unspecified vulnerabilities in Lyris ListManager 8.x prior to 8.95d, 9.2 prior to 9.2c, and 9.3 prior to 9.3b allow remote malicious users to (1) gain list administrator privileges or (2) access arbitrary mailing lists via unknown vectors related to modification of clien...
Lyris List Manager 8.95a
Lyris List Manager 9.2b
Lyris List Manager 8.95
Lyris List Manager 8.95c
Lyris List Manager 9.3a
Lyris List Manager 9.2
Lyris List Manager 9.2a
Lyris List Manager 9.3
Lyris List Manager 8.95b
578
VMScore
CVE-2006-4547
Lyris ListManager 8.95 allows remote authenticated users to obtain sensitive information by attempting to add a user with a ' (single quote) character in the name, which reveals the details of the underlying SQL query, possibly because of a forced SQL error or SQL injection.
Lyris List Manager 8.95
578
VMScore
CVE-2006-4546
Lyris ListManager 8.95 allows remote authenticated users, who have administrative privileges for at least one list on the server, to add new administrators to any list via a modified MEMBERS_.List_ parameter.
Lyris List Manager 8.95
445
VMScore
CVE-2005-4148
Lyris ListManager 8.5, and possibly other versions prior to 8.8, includes sensitive information in the env hidden variable, which allows remote malicious users to obtain information such as the installation path by requesting a non-existent page and reading the env variable from ...
Lyris Technologies Inc Listmanager 5.0
Lyris Technologies Inc Listmanager 8.0
Lyris Technologies Inc Listmanager 8.8a
Lyris Technologies Inc Listmanager 6.0
Lyris Technologies Inc Listmanager 7.0
445
VMScore
CVE-2005-4149
Lyris ListManager 8.8 up to and including 8.9b allows remote malicious users to obtain sensitive information by causing errors in TML scripts, such as via direct requests, which leaks the installation path, SQL queries, or product code in diagnostic messages.
Lyris Technologies Inc Listmanager 5.0
Lyris Technologies Inc Listmanager 8.0
Lyris Technologies Inc Listmanager 8.8a
Lyris Technologies Inc Listmanager 6.0
Lyris Technologies Inc Listmanager 7.0
755
VMScore
CVE-2005-4143
SQL injection vulnerability in Lyris ListManager 5.0 up to and including 8.9a allows remote malicious users to execute arbitrary SQL commands via SQL code after a numeric argument to a /read/attachment URL.
Lyris List Manager 5.0
Lyris List Manager 7.0
Lyris List Manager 6.0
Lyris List Manager 8.0
Lyris List Manager 8.8a
1 EDB exploit
445
VMScore
CVE-2005-4146
Lyris ListManager prior to 8.9b allows remote malicious users to obtain sensitive information via a request to the TCLHTTPd status module, which provides sensitive server configuration information.
Lyris Technologies Inc Listmanager 5.0
Lyris Technologies Inc Listmanager 8.0
Lyris Technologies Inc Listmanager 8.8a
Lyris Technologies Inc Listmanager 6.0
Lyris Technologies Inc Listmanager 7.0
668
VMScore
CVE-2005-4142
The web interface for subscribing new users in Lyris ListManager 5.0 up to and including 8.8b, in combination with a line wrap feature, allows remote malicious users to execute arbitrary list administration commands via LFCR (%0A%0D) sequences in the pw parameter. NOTE: it is not...
Lyris Technologies Inc Listmanager 5.0
Lyris Technologies Inc Listmanager 8.0
Lyris Technologies Inc Listmanager 8.8a
Lyris Technologies Inc Listmanager 6.0
Lyris Technologies Inc Listmanager 7.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23692
CVE-2012-1823
memory leak
CVE-2024-0627
CVE-2024-31402
privilege escalation
CVE-2024-36418
remote code execution
CVE-2024-27844
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »