5
CVE-2005-4148
- EPSS 1.78%
- Veröffentlicht 10.12.2005 11:03:00
- Zuletzt bearbeitet 16.06.2026 22:18:15
- Erkennungen
Lyris ListManager 8.5, and possibly other versions before 8.8, includes sensitive information in the env hidden variable, which allows remote attackers to obtain information such as the installation path by requesting a non-existent page and reading the env variable from the resulting error message page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lyris Technologies Inc ≫ Listmanager Version 5.0
Lyris Technologies Inc ≫ Listmanager Version 6.0
Lyris Technologies Inc ≫ Listmanager Version 7.0
Lyris Technologies Inc ≫ Listmanager Version 8.0
Lyris Technologies Inc ≫ Listmanager Version 8.8a
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.78% | 0.754 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0349.html
http://metasploit.com/research/vulns/lyris_listmanager/
http://secunia.com/advisories/17943
http://www.securityfocus.com/archive/1/419077/100/0/threaded
http://www.vupen.com/english/advisories/2005/2820
http://www.osvdb.org/21552
http://www.securityfocus.com/bid/15789