Home/Product/lyris list manager
Product

lyris list manager

15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2014-5188
all versions
Cross-site scripting (XSS) vulnerability in doemailpassword.tml in Lyris ListManager (LM) 8.95a allows remote attackers to inject
CVE-2008-2923
all versions
Cross-site scripting (XSS) vulnerability in read/search/results in Lyris ListManager 8.8, 8.95, and 9.3d allows remote attackers t
CVE-2007-6319
all versions
Multiple unspecified vulnerabilities in Lyris ListManager 8.x before 8.95d, 9.2 before 9.2c, and 9.3 before 9.3b allow remote atta
CVE-2006-4547
all versions
Lyris ListManager 8.95 allows remote authenticated users to obtain sensitive information by attempting to add a user with a ' (sin
CVE-2006-4546
all versions
Lyris ListManager 8.95 allows remote authenticated users, who have administrative privileges for at least one list on the server,
CVE-2005-4149
all versions
Lyris ListManager 8.8 through 8.9b allows remote attackers to obtain sensitive information by causing errors in TML scripts, such
CVE-2005-4148
all versions
Lyris ListManager 8.5, and possibly other versions before 8.8, includes sensitive information in the env hidden variable, which al
CVE-2005-4147
all versions
The TCLHTTPd service in Lyris ListManager before 8.9b allows remote attackers to obtain source code for arbitrary .tml (TCL) files
CVE-2005-4146
all versions
Lyris ListManager before 8.9b allows remote attackers to obtain sensitive information via a request to the TCLHTTPd status module,
CVE-2005-4145
all versions
The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with a small se
CVE-2005-4144
all versions
Lyris ListManager 5.0 through 8.9a allows remote attackers to add "ORDER BY" columns to SQL queries via unusual whitespace charact
CVE-2005-4143
all versions
SQL injection vulnerability in Lyris ListManager 5.0 through 8.9a allows remote attackers to execute arbitrary SQL commands via SQ
CVE-2005-4142
all versions
The web interface for subscribing new users in Lyris ListManager 5.0 through 8.8b, in combination with a line wrap feature, allows
CVE-2000-0863
<= 2.96
Buffer overflow in listmanager earlier than 2.105.1 allows local users to gain additional privileges.
CVE-2000-0758
all versions
The web interface for Lyris List Manager 3 and 4 allows list subscribers to obtain administrative access by modifying the value of
threatengine.sh