5
CVSSv2

CVE-2005-4148

Published: 10/12/2005 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Lyris ListManager 8.5, and possibly other versions prior to 8.8, includes sensitive information in the env hidden variable, which allows remote malicious users to obtain information such as the installation path by requesting a non-existent page and reading the env variable from the resulting error message page.

Vulnerable Product Search on Vulmon Subscribe to Product

lyris technologies inc listmanager 5.0

lyris technologies inc listmanager 6.0

lyris technologies inc listmanager 7.0

lyris technologies inc listmanager 8.0

lyris technologies inc listmanager 8.8a