PT-2000-1690 · Lyris · Lyris Listmanager

Published

2000-10-20

·

Updated

2008-09-05

·

CVE-2000-0758

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Lyris List Manager versions 3 and 4
Description The issue allows list subscribers to gain administrative access through the web interface by modifying the value of the list admin hidden form field.
Recommendations For Lyris List Manager versions 3 and 4, consider restricting access to the web interface until a fix is available, and avoid using the list admin hidden form field to prevent exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0758

Affected Products

Lyris Listmanager