Lyris ListManager 5.0 through 8.9a allows remote attackers to add "ORDER BY" columns to SQL queries via unusual whitespace characters in the orderby parameter, such as (1) newlines and (2) 0xFF (ASCII 255) characters, which are interpreted as whitespace.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-12-10T11:00:00

Updated: 2024-08-07T23:38:50.566Z

Reserved: 2005-12-10T00:00:00

Link: CVE-2005-4144

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2005-12-10T11:03:00.000

Modified: 2018-10-19T15:40:25.080

Link: CVE-2005-4144

cve-icon Redhat

No data.