6.5
CVSSv2

CVE-2005-4145

Published: 10/12/2005 Updated: 19/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The MSDE version of Lyris ListManager 5.0 up to and including 8.9b configures the sa account in the database to use a password with a small search space ("lyris" and up to 5 digits, possibly from the process ID), which allows remote malicious users to gain access via a brute force attack.

Vulnerable Product Search on Vulmon Subscribe to Product

lyris technologies inc listmanager 6.0

lyris technologies inc listmanager 7.0

lyris technologies inc listmanager 8.0

lyris technologies inc listmanager 8.8a

lyris technologies inc listmanager 5.0

Exploits

## # $Id: lyris_listmanager_weak_passrb 10394 2010-09-20 08:06:27Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/ ...