Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8prw-qcgj-xjrj

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The web interface for subscribing new users in Lyris ListManager 5.0 through 8.8b, in combination with a line wrap feature, allows remote attackers to execute arbitrary list administration commands via LFCR (%0A%0D) sequences in the pw parameter. NOTE: it is not clear whether this is a variant of a CRLF injection vulnerability.

The web interface for subscribing new users in Lyris ListManager 5.0 through 8.8b, in combination with a line wrap feature, allows remote attackers to execute arbitrary list administration commands via LFCR (%0A%0D) sequences in the pw parameter. NOTE: it is not clear whether this is a variant of a CRLF injection vulnerability.

EPSS

Процентиль: 83%
0.01867
Низкий

Связанные уязвимости

nvd
около 20 лет назад

The web interface for subscribing new users in Lyris ListManager 5.0 through 8.8b, in combination with a line wrap feature, allows remote attackers to execute arbitrary list administration commands via LFCR (%0A%0D) sequences in the pw parameter. NOTE: it is not clear whether this is a variant of a CRLF injection vulnerability.

EPSS

Процентиль: 83%
0.01867
Низкий