7.5
CVSSv2

CVE-2005-0157

Published: 03/05/2005 Updated: 10/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The confirm add-on in SmartList 3.15 and previous versions allows malicious users to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie was assigned.

Vulnerable Product Search on Vulmon Subscribe to Product

smartlist smartlist

Vendor Advisories

Jeroen van Wolffelaar noticed that the confirm add-on of SmartList, the listmanager used on listsdebianorg, which is used on that host as well, could be tricked to subscribe arbitrary addresses to the lists For the stable distribution (woody) this problem has been fixed in version 315-5woody1 For the unstable distribution (sid) this problem ...