SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-4147

The TCLHTTPd service in Lyris ListManager before 8.9b allows remote attackers to obtain source code for arbitrary .tml (TCL) files via (1) a request with a trailing null byte (%00), which might also require (2) an authentication bypass step that…

MEDIUM 6.5EPSS 1.92%

Does this matter?

Lower severity and a low EPSS score (1.92%). Track it; it rarely justifies an emergency change on its own.

Description

The TCLHTTPd service in Lyris ListManager before 8.9b allows remote attackers to obtain source code for arbitrary .tml (TCL) files via (1) a request with a trailing null byte (%00), which might also require (2) an authentication bypass step that involves a username with a trailing "@" characters.

CVSS 2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
1.92% probability · 79th percentile
CISA KEV
Not listed
Affected
lyris technologies inc/listmanager
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.