Lyris ListManager Command Execution Vulnerability
BID:15786
Info
Lyris ListManager Command Execution Vulnerability
| Bugtraq ID: | 15786 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2005 12:00AM |
| Updated: | Dec 09 2005 12:00AM |
| Credit: | H D Moore is credited with the discovery of this vulnerability. |
| Vulnerable: |
Lyris List Manager 8.8 a Lyris List Manager 8.0 Lyris List Manager 7.0 Lyris List Manager 6.0 Lyris List Manager 5.0 |
| Not Vulnerable: | |
Discussion
Lyris ListManager Command Execution Vulnerability
Lyris ListManager is prone to a CRLF injection vulnerability.
Attackers may exploit this weakness to execute list manager administrative commands, and manipulate the structure of outgoing messages. For example, it may be possible for attackers to set the recipient to an arbitrary value.
Versions 5.0 through 8.8a are vulnerable; other versions may also be affected.
Lyris ListManager is prone to a CRLF injection vulnerability.
Attackers may exploit this weakness to execute list manager administrative commands, and manipulate the structure of outgoing messages. For example, it may be possible for attackers to set the recipient to an arbitrary value.
Versions 5.0 through 8.8a are vulnerable; other versions may also be affected.
Exploit / POC
Lyris ListManager Command Execution Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Lyris ListManager Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.