CVE-2006-3483
Summary
| CVE | CVE-2006-3483 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-10 20:05:00 UTC |
| Updated | 2008-09-05 21:07:00 UTC |
| Description | PHPMailList 1.8.0 stores sensitive information under the web document root iwth insufficient access control, which allows remote attackers to obtain email addresses of subscribers, configuration information, and the admin username and password via direct requests to (1) list.dat or (2) ml_config.dat. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Phpmaillist | Phpmaillist | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PHPMailList Discloses Information and Passwords to Remote Users and Permits Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | securitytracker.com | |
| 27018 | OSVDB | www.osvdb.org | |
| Lostmon´s Blogger: Multiple Vulnerabilities in PHPMailList 1.8.0 | MISC | lostmon.blogspot.com | |
| 27017 | OSVDB | www.osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.