List Manager

Vendor:

First CVE: Oct 20, 2000 · Active for 25 years

8
Total CVEs
More Total CVEs than 85% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact List Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2000
25 years ago
Most Recent CVE
Aug 7, 2014
4,370 days ago

CVE Severity & Scoring

List Manager8 CVEs
All CVEs352,708 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SQL injection vulnerability in Lyris ListManager 5.0 through 8.9a allows remote attackers to execute arbitrary SQL commands via SQL code after a numeric argument to a /read/attachm
Dec 10, 20057.528NOYES
Multiple unspecified vulnerabilities in Lyris ListManager 8.x before 8.95d, 9.2 before 9.2c, and 9.3 before 9.3b allow remote attackers to (1) gain list administrator privileges or
Feb 19, 200810.027NONO
Lyris ListManager 5.0 through 8.9a allows remote attackers to add "ORDER BY" columns to SQL queries via unusual whitespace characters in the orderby parameter, such as (1) newlines
Dec 10, 20057.520NONO
Lyris ListManager 8.95 allows remote authenticated users to obtain sensitive information by attempting to add a user with a ' (single quote) character in the name, which reveals th
Sep 6, 20066.519NONO
Cross-site scripting (XSS) vulnerability in doemailpassword.tml in Lyris ListManager (LM) 8.95a allows remote attackers to inject arbitrary web script or HTML via the EmailAddr par
Aug 7, 20144.318NONO
Lyris ListManager 8.95 allows remote authenticated users, who have administrative privileges for at least one list on the server, to add new administrators to any list via a modifi
Sep 6, 20066.518NONO
Cross-site scripting (XSS) vulnerability in read/search/results in Lyris ListManager 8.8, 8.95, and 9.3d allows remote attackers to inject arbitrary web script or HTML via the word
Jun 30, 20084.314NONO
The web interface for Lyris List Manager 3 and 4 allows list subscribers to obtain administrative access by modifying the value of the list_admin hidden form field.
Oct 20, 20004.614NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For List Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.3d14.31.3%00
9.3a110.02.6%00
9.3110.02.6%00
9.2b110.02.6%00
9.2a110.02.6%00
9.2110.02.6%00
8.95c110.02.6%00
8.95b110.02.6%00
8.95a27.22.2%00
8.9546.81.5%00
8.8a27.51.6%01
8.814.31.3%00
8.027.51.6%01
7.027.51.6%01
6.027.51.6%01
5.027.51.6%01
4.014.60.4%00
3.014.60.4%00