VulnerabilityModified
CVE-2006-4546
Lyris ListManager 8.95 allows remote authenticated users, who have administrative privileges for at least one list on the server, to add new administrators to any list via a modified MEMBERS_.List_ parameter.
MEDIUM 6.5EPSS 1.37%
Does this matter?
Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.
Description
Lyris ListManager 8.95 allows remote authenticated users, who have administrative privileges for at least one list on the server, to add new administrators to any list via a modified MEMBERS_.List_ parameter.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Affected
- lyris/list manager
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0817.html
- http://secunia.com/advisories/21698
- http://securityreason.com/securityalert/1502
- http://securitytracker.com/id?1016771
- http://www.securityfocus.com/archive/1/444844/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28679
- http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0817.html
- http://secunia.com/advisories/21698
- http://securityreason.com/securityalert/1502
- http://securitytracker.com/id?1016771
- http://www.securityfocus.com/archive/1/444844/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28679
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.