CVE-2005-4144
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/12/2005
Last modified:
03/04/2025
Description
Lyris ListManager 5.0 through 8.9a allows remote attackers to add "ORDER BY" columns to SQL queries via unusual whitespace characters in the orderby parameter, such as (1) newlines and (2) 0xFF (ASCII 255) characters, which are interpreted as whitespace.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:lyris:list_manager:5.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:lyris:list_manager:6.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:lyris:list_manager:7.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:lyris:list_manager:8.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:lyris:list_manager:8.8a:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0349.html
- http://metasploit.com/research/vulns/lyris_listmanager/
- http://secunia.com/advisories/17943
- http://www.osvdb.org/21549
- http://www.securityfocus.com/archive/1/419077/100/0/threaded
- http://www.securityfocus.com/bid/15787
- http://www.vupen.com/english/advisories/2005/2820
- http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0349.html
- http://metasploit.com/research/vulns/lyris_listmanager/
- http://secunia.com/advisories/17943
- http://www.osvdb.org/21549
- http://www.securityfocus.com/archive/1/419077/100/0/threaded
- http://www.securityfocus.com/bid/15787
- http://www.vupen.com/english/advisories/2005/2820