CVE-2005-4143
Published Dec 10, 2005
Last updated 6 years ago
Overview
- Description
- SQL injection vulnerability in Lyris ListManager 5.0 through 8.9a allows remote attackers to execute arbitrary SQL commands via SQL code after a numeric argument to a /read/attachment URL.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:lyris:list_manager:5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ADBC9CAC-358F-42FD-8E63-99843572C060" }, { "criteria": "cpe:2.3:a:lyris:list_manager:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3E9319DE-2B5B-494F-B8AD-8455F7823393" }, { "criteria": "cpe:2.3:a:lyris:list_manager:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "22CE39BD-2DE3-43D8-B1AF-E331EDDABF99" }, { "criteria": "cpe:2.3:a:lyris:list_manager:8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "19017E4F-FBF3-4EF1-8835-100CE349E2F9" }, { "criteria": "cpe:2.3:a:lyris:list_manager:8.8a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B97018D-CC7C-42F2-B4AF-11ECEB02353A" } ], "operator": "OR" } ] } ]