7.5
CVSSv2

CVE-2005-4142

Published: 10/12/2005 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The web interface for subscribing new users in Lyris ListManager 5.0 up to and including 8.8b, in combination with a line wrap feature, allows remote malicious users to execute arbitrary list administration commands via LFCR (%0A%0D) sequences in the pw parameter. NOTE: it is not clear whether this is a variant of a CRLF injection vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

lyris technologies inc listmanager 7.0

lyris technologies inc listmanager 8.0

lyris technologies inc listmanager 8.8a

lyris technologies inc listmanager 5.0

lyris technologies inc listmanager 6.0