CVE-2012-2352

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
31/05/2012
Last modified:
11/04/2025

Description

The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers to list, read, and delete arbitrary list archives via vectors related to the (1) do_arc_manage, (2) do_arc_download, or (3) do_arc_delete functions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sympa:sympa:*:*:*:*:*:*:*:* 6.1.10 (including)
cpe:2.3:a:sympa:sympa:0.001:*:*:*:*:*:*:*
cpe:2.3:a:sympa:sympa:0.002:*:*:*:*:*:*:*
cpe:2.3:a:sympa:sympa:0.003:*:*:*:*:*:*:*
cpe:2.3:a:sympa:sympa:0.004:*:*:*:*:*:*:*
cpe:2.3:a:sympa:sympa:0.005:*:*:*:*:*:*:*
cpe:2.3:a:sympa:sympa:0.006:*:*:*:*:*:*:*
cpe:2.3:a:sympa:sympa:0.007:*:*:*:*:*:*:*
cpe:2.3:a:sympa:sympa:0.008:*:*:*:*:*:*:*
cpe:2.3:a:sympa:sympa:0.009:*:*:*:*:*:*:*
cpe:2.3:a:sympa:sympa:0.010:*:*:*:*:*:*:*
cpe:2.3:a:sympa:sympa:0.011:*:*:*:*:*:*:*
cpe:2.3:a:sympa:sympa:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:sympa:sympa:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:sympa:sympa:1.2.2:*:*:*:*:*:*:*