5
CVE-2005-4148
- EPSS 0.76%
- Veröffentlicht 10.12.2005 11:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Lyris ListManager 8.5, and possibly other versions before 8.8, includes sensitive information in the env hidden variable, which allows remote attackers to obtain information such as the installation path by requesting a non-existent page and reading the env variable from the resulting error message page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lyris Technologies Inc ≫ Listmanager Version5.0
Lyris Technologies Inc ≫ Listmanager Version6.0
Lyris Technologies Inc ≫ Listmanager Version7.0
Lyris Technologies Inc ≫ Listmanager Version8.0
Lyris Technologies Inc ≫ Listmanager Version8.8a
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.76% | 0.71 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|