The web interface for subscribing new users in Lyris ListManager 5.0 through 8.8b, in combination with a line wrap feature, allows remote attackers to execute arbitrary list administration commands via LFCR (%0A%0D) sequences in the pw parameter. NOTE: it is not clear whether this is a variant of a CRLF injection vulnerability.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-12-10T11:00:00

Updated: 2024-08-07T23:38:51.996Z

Reserved: 2005-12-10T00:00:00

Link: CVE-2005-4142

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2005-12-10T11:03:00.000

Modified: 2018-10-19T15:40:24.113

Link: CVE-2005-4142

cve-icon Redhat

No data.