Vulnerabilities > CVE-2007-6319 - Unspecified vulnerability in Lyris List Manager
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN lyris
nessus
Summary
Multiple unspecified vulnerabilities in Lyris ListManager 8.x before 8.95d, 9.2 before 9.2c, and 9.3 before 9.3b allow remote attackers to (1) gain list administrator privileges or (2) access arbitrary mailing lists via unknown vectors related to modification of client-side information; and (3) allow remote authenticated administrators to modify other account data by creating "new accounts that collide with existing accounts."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 9 |
Nessus
NASL family | CGI abuses |
NASL id | LISTMANAGER_93B.NASL |
description | The remote host is running ListManager, a web-based commercial mailing list management application from Lyris. According to its banner, the version of ListManager installed on the remote host relies on client-side code to validate unspecified form parameters before processing them. An attacker who is subscribed to a list managed by the affected application can reportedly leverage this issue to elevate his privileges to list administrator or gain access to arbitrary mailing lists. In addition, once administrative access has been granted, another vulnerability in ListManager |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 31134 |
published | 2008-02-22 |
reporter | This script is Copyright (C) 2008-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/31134 |
title | ListManager < 9.3b / 9.2c / 8.95d Multiple Vulnerabilities |
code |
|
References
- http://secunia.com/advisories/29019
- http://secunia.com/advisories/29019
- http://securityreason.com/securityalert/3671
- http://securityreason.com/securityalert/3671
- http://securitytracker.com/id?1019436
- http://securitytracker.com/id?1019436
- http://www.securityfocus.com/archive/1/488343/100/0/threaded
- http://www.securityfocus.com/archive/1/488343/100/0/threaded
- http://www.securityfocus.com/bid/26792
- http://www.securityfocus.com/bid/26792
- http://www.vupen.com/english/advisories/2008/0618
- http://www.vupen.com/english/advisories/2008/0618