7.5
CVE-2005-4144
- EPSS 1.2%
- Veröffentlicht 10.12.2005 11:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Lyris ListManager 5.0 through 8.9a allows remote attackers to add "ORDER BY" columns to SQL queries via unusual whitespace characters in the orderby parameter, such as (1) newlines and (2) 0xFF (ASCII 255) characters, which are interpreted as whitespace.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lyris ≫ List Manager Version5.0
Lyris ≫ List Manager Version6.0
Lyris ≫ List Manager Version7.0
Lyris ≫ List Manager Version8.0
Lyris ≫ List Manager Version8.8a
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.2% | 0.77 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|