Vulnerabilities > CVE-2003-1367 - Configuration vulnerability in Great Circle Associates Majordomo 1.94.4/1.94.5

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
NONE
Availability impact
NONE
network
low complexity
great-circle-associates
CWE-16

Summary

The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allows remote attackers to identify the email addresses of members of mailing lists via a "which" command.

Common Weakness Enumeration (CWE)