Multiple unspecified vulnerabilities in Lyris ListManager 8.x before 8.95d, 9.2 before 9.2c, and 9.3 before 9.3b allow remote attackers to (1) gain list administrator privileges or (2) access arbitrary mailing lists via unknown vectors related to modification of client-side information; and (3) allow remote authenticated administrators to modify other account data by creating "new accounts that collide with existing accounts."
2008-02-19T22:44:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | lyris | list_manager | 8.95 | Yes |
Application | lyris | list_manager | 8.95a | Yes |
Application | lyris | list_manager | 8.95b | Yes |
Application | lyris | list_manager | 8.95c | Yes |
Application | lyris | list_manager | 9.2 | Yes |
Application | lyris | list_manager | 9.2a | Yes |
Application | lyris | list_manager | 9.2b | Yes |
Application | lyris | list_manager | 9.3 | Yes |
Application | lyris | list_manager | 9.3a | Yes |