6.5
CVSSv2

CVE-2005-4147

Published: 10/12/2005 Updated: 19/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The TCLHTTPd service in Lyris ListManager prior to 8.9b allows remote malicious users to obtain source code for arbitrary .tml (TCL) files via (1) a request with a trailing null byte (%00), which might also require (2) an authentication bypass step that involves a username with a trailing "@" characters.

Vulnerable Product Search on Vulmon Subscribe to Product

lyris technologies inc listmanager 5.0

lyris technologies inc listmanager 6.0

lyris technologies inc listmanager 7.0

lyris technologies inc listmanager 8.0

lyris technologies inc listmanager 8.8a