Sympa

Sympa

13 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Published 31.12.2023 05:15:08
  • Last modified 17.04.2025 20:15:21

Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value. Specifically, the cookie parameter is both a salt for stored passwords and an XSS protect...

Exploit
  • EPSS 1.04%
  • Published 10.12.2020 08:15:11
  • Last modified 21.11.2024 05:24:24

Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.

  • EPSS 0.16%
  • Published 10.10.2020 18:15:12
  • Last modified 21.11.2024 05:20:31

debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)

  • EPSS 0.04%
  • Published 07.10.2020 18:15:12
  • Last modified 21.11.2024 05:20:24

Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable...

Exploit
  • EPSS 0.11%
  • Published 27.05.2020 18:15:12
  • Last modified 21.11.2024 04:56:24

Sympa before 6.2.56 allows privilege escalation.

  • EPSS 2.12%
  • Published 24.02.2020 18:15:22
  • Last modified 21.11.2024 05:40:29

Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters.

  • EPSS 0.88%
  • Published 06.09.2018 18:29:00
  • Last modified 21.11.2024 03:40:22

sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. Thi...

  • EPSS 0.47%
  • Published 26.06.2018 16:29:02
  • Last modified 21.11.2024 03:40:10

The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server filesystem. This attack appear to ...

  • EPSS 0.59%
  • Published 22.01.2015 15:59:00
  • Last modified 12.04.2025 10:46:40

The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers to read arbitrary files via unspecified vectors.

  • EPSS 1.25%
  • Published 31.05.2012 17:55:04
  • Last modified 11.04.2025 00:51:21

The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers to list, read, and delete arbitrary list archives via vectors related to the (1) do_arc_manage, (2) d...