CVE-2021-46900
- EPSS 0.13%
- Veröffentlicht 31.12.2023 05:15:08
- Zuletzt bearbeitet 17.04.2025 20:15:21
Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value. Specifically, the cookie parameter is both a salt for stored passwords and an XSS protect...
CVE-2020-29668
- EPSS 1.04%
- Veröffentlicht 10.12.2020 08:15:11
- Zuletzt bearbeitet 21.11.2024 05:24:24
Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
CVE-2020-26932
- EPSS 0.16%
- Veröffentlicht 10.10.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:20:31
debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)
CVE-2020-26880
- EPSS 0.04%
- Veröffentlicht 07.10.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:20:24
Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable...
CVE-2020-10936
- EPSS 0.11%
- Veröffentlicht 27.05.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:24
Sympa before 6.2.56 allows privilege escalation.
CVE-2020-9369
- EPSS 2.12%
- Veröffentlicht 24.02.2020 18:15:22
- Zuletzt bearbeitet 21.11.2024 05:40:29
Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters.
CVE-2018-1000671
- EPSS 0.88%
- Veröffentlicht 06.09.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:22
sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. Thi...
CVE-2018-1000550
- EPSS 0.47%
- Veröffentlicht 26.06.2018 16:29:02
- Zuletzt bearbeitet 21.11.2024 03:40:10
The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server filesystem. This attack appear to ...
- EPSS 0.59%
- Veröffentlicht 22.01.2015 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2012-2352
- EPSS 1.25%
- Veröffentlicht 31.05.2012 17:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers to list, read, and delete arbitrary list archives via vectors related to the (1) do_arc_manage, (2) d...