CVE-2005-4148
N/A
N/A
Summary
Lyris ListManager 8.5, and possibly other versions before 8.8, includes sensitive information in the env hidden variable, which allows remote attackers to obtain information such as the installation path by requesting a non-existent page and reading the env variable from the resulting error message page.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securityfocus.com/archive/1/419077/100/0/threaded
- http://metasploit.com/research/vulns/lyris_listmanager/
- http://www.securityfocus.com/bid/15789
- http://www.vupen.com/english/advisories/2005/2820
- http://www.osvdb.org/21552
- http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0349.html
- http://secunia.com/advisories/17943
References
- http://www.securityfocus.com/archive/1/419077/100/0/threaded
- http://metasploit.com/research/vulns/lyris_listmanager/
- http://www.securityfocus.com/bid/15789
- http://www.vupen.com/english/advisories/2005/2820
- http://www.osvdb.org/21552
- http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0349.html
- http://secunia.com/advisories/17943
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.