Lyris ListManager Unauthorized Administrative User Addition Vulnerability
BID:19784
Info
Lyris ListManager Unauthorized Administrative User Addition Vulnerability
| Bugtraq ID: | 19784 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2006 12:00AM |
| Updated: | Sep 05 2006 04:08PM |
| Credit: | Design Properly is credited with the discovery of this vulnerability. |
| Vulnerable: |
Lyris ListManager 8.95 |
| Not Vulnerable: | |
Discussion
Lyris ListManager Unauthorized Administrative User Addition Vulnerability
Lyris ListManager is prone to a design flaw that facilitates the addition of an unauthorized administrative user. The issue derives from the use of hidden form fields in the 'add administrator' form.
Attackers with administrative privileges to a Lyris list may exploit this vulnerability to add administrative users to arbitrary lists hosted on the same server. For example, an administrator for List-A can maliciously modify hidden form fields when conventionally adding an administrative user, causing that user to be added as an administrator to List-B.
Version 8.95 is vulnerable; other versions may also be affected.
Lyris ListManager is prone to a design flaw that facilitates the addition of an unauthorized administrative user. The issue derives from the use of hidden form fields in the 'add administrator' form.
Attackers with administrative privileges to a Lyris list may exploit this vulnerability to add administrative users to arbitrary lists hosted on the same server. For example, an administrator for List-A can maliciously modify hidden form fields when conventionally adding an administrative user, causing that user to be added as an administrator to List-B.
Version 8.95 is vulnerable; other versions may also be affected.
Exploit / POC
Lyris ListManager Unauthorized Administrative User Addition Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Lyris ListManager Unauthorized Administrative User Addition Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Lyris ListManager Unauthorized Administrative User Addition Vulnerability
References:
References:
- List Manager Homepage (Lyris)