CVE-2005-4147
The TCLHTTPd service in Lyris ListManager before 8.9b allows remote attackers to obtain source code for arbitrary .tml (TCL) files via (1) a request with a trailing null byte (%00), which might also require (2) an authentication bypass step that…
Does this matter?
Lower severity and a low EPSS score (1.92%). Track it; it rarely justifies an emergency change on its own.
Description
The TCLHTTPd service in Lyris ListManager before 8.9b allows remote attackers to obtain source code for arbitrary .tml (TCL) files via (1) a request with a trailing null byte (%00), which might also require (2) an authentication bypass step that involves a username with a trailing "@" characters.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.92% probability · 79th percentile
- CISA KEV
- Not listed
- Affected
- lyris technologies inc/listmanager
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0349.html
- http://metasploit.com/research/vulns/lyris_listmanager/Exploit, Patch
- http://secunia.com/advisories/17943Exploit, Patch, Vendor Advisory
- http://www.osvdb.org/21551Exploit, Patch
- http://www.osvdb.org/21573Exploit, Patch
- http://www.securityfocus.com/archive/1/419077/100/0/threaded
- http://www.securityfocus.com/bid/15788Patch
- http://www.vupen.com/english/advisories/2005/2820
- http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0349.html
- http://metasploit.com/research/vulns/lyris_listmanager/Exploit, Patch
- http://secunia.com/advisories/17943Exploit, Patch, Vendor Advisory
- http://www.osvdb.org/21551Exploit, Patch
- http://www.osvdb.org/21573Exploit, Patch
- http://www.securityfocus.com/archive/1/419077/100/0/threaded
- http://www.securityfocus.com/bid/15788Patch
- http://www.vupen.com/english/advisories/2005/2820
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.