Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-4148

Опубликовано: 10 дек. 2005
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Lyris ListManager 8.5, and possibly other versions before 8.8, includes sensitive information in the env hidden variable, which allows remote attackers to obtain information such as the installation path by requesting a non-existent page and reading the env variable from the resulting error message page.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:lyris_technologies_inc:listmanager:5.0:*:*:*:*:*:*:*
cpe:2.3:a:lyris_technologies_inc:listmanager:6.0:*:*:*:*:*:*:*
cpe:2.3:a:lyris_technologies_inc:listmanager:7.0:*:*:*:*:*:*:*
cpe:2.3:a:lyris_technologies_inc:listmanager:8.0:*:*:*:*:*:*:*
cpe:2.3:a:lyris_technologies_inc:listmanager:8.8a:*:*:*:*:*:*:*

EPSS

Процентиль: 73%
0.00762
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Lyris ListManager 8.5, and possibly other versions before 8.8, includes sensitive information in the env hidden variable, which allows remote attackers to obtain information such as the installation path by requesting a non-existent page and reading the env variable from the resulting error message page.

EPSS

Процентиль: 73%
0.00762
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other