Lucene search

K
cve[email protected]CVE-2012-2352
HistoryMay 31, 2012 - 5:55 p.m.

CVE-2012-2352

2012-05-3117:55:04
CWE-264
web.nvd.nist.gov
33
sympa
archive management
remote attack
cve-2012-2352
security vulnerability
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.6%

The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers to list, read, and delete arbitrary list archives via vectors related to the (1) do_arc_manage, (2) do_arc_download, or (3) do_arc_delete functions.

Affected configurations

NVD
Node
sympasympaRange6.1.10
OR
sympasympaMatch0.001
OR
sympasympaMatch0.002
OR
sympasympaMatch0.003
OR
sympasympaMatch0.004
OR
sympasympaMatch0.005
OR
sympasympaMatch0.006
OR
sympasympaMatch0.007
OR
sympasympaMatch0.008
OR
sympasympaMatch0.009
OR
sympasympaMatch0.010
OR
sympasympaMatch0.011
OR
sympasympaMatch1.2.0
OR
sympasympaMatch1.2.1
OR
sympasympaMatch1.2.2
OR
sympasympaMatch1.3.0
OR
sympasympaMatch1.3.1
OR
sympasympaMatch1.3.1-2
OR
sympasympaMatch1.3.2
OR
sympasympaMatch1.3.3
OR
sympasympaMatch1.3.4
OR
sympasympaMatch1.3.4-1
OR
sympasympaMatch1.4.0
OR
sympasympaMatch1.4.1
OR
sympasympaMatch1.4.2
OR
sympasympaMatch1.4.2-1
OR
sympasympaMatch1.5
OR
sympasympaMatch2.2.1b
OR
sympasympaMatch2.2.2b
OR
sympasympaMatch2.2.3b
OR
sympasympaMatch2.2.4
OR
sympasympaMatch2.2.5
OR
sympasympaMatch2.2.6
OR
sympasympaMatch2.2.7
OR
sympasympaMatch2.2b
OR
sympasympaMatch2.3beta
OR
sympasympaMatch2.3.0
OR
sympasympaMatch2.3.1
OR
sympasympaMatch2.3.2
OR
sympasympaMatch2.3.3
OR
sympasympaMatch2.3.4
OR
sympasympaMatch2.4
OR
sympasympaMatch2.5
OR
sympasympaMatch2.5.1
OR
sympasympaMatch2.5.2
OR
sympasympaMatch2.5.3b
OR
sympasympaMatch2.5.4b
OR
sympasympaMatch2.6
OR
sympasympaMatch2.6.1
OR
sympasympaMatch2.7
OR
sympasympaMatch2.7.1
OR
sympasympaMatch2.7.2
OR
sympasympaMatch2.7.3
OR
sympasympaMatch2.7a
OR
sympasympaMatch2.7b.1
OR
sympasympaMatch2.7b.2
OR
sympasympaMatch2.7b.3
OR
sympasympaMatch3.0
OR
sympasympaMatch3.0a
OR
sympasympaMatch3.0a.1
OR
sympasympaMatch3.0b.4
OR
sympasympaMatch3.0b.8
OR
sympasympaMatch3.0b.9
OR
sympasympaMatch3.1
OR
sympasympaMatch3.1.1
OR
sympasympaMatch3.1b.7
OR
sympasympaMatch3.1b.8
OR
sympasympaMatch3.1b.9
OR
sympasympaMatch3.1b.10
OR
sympasympaMatch3.1b.12
OR
sympasympaMatch3.1b.13
OR
sympasympaMatch3.2
OR
sympasympaMatch3.2.1
OR
sympasympaMatch3.2.2a
OR
sympasympaMatch3.3
OR
sympasympaMatch3.3.1
OR
sympasympaMatch3.3.3
OR
sympasympaMatch3.3.4b.3
OR
sympasympaMatch3.3.4b.4
OR
sympasympaMatch3.3.4b.5
OR
sympasympaMatch3.3.4b.6
OR
sympasympaMatch3.3.4b.7
OR
sympasympaMatch3.3.4b.8
OR
sympasympaMatch3.3.4b.9
OR
sympasympaMatch3.3.5
OR
sympasympaMatch3.3.6b.1
OR
sympasympaMatch3.3.6b.2
OR
sympasympaMatch3.3.6b.3
OR
sympasympaMatch3.3.6b.4
OR
sympasympaMatch3.3.6b.5
OR
sympasympaMatch3.3.6b.6
OR
sympasympaMatch3.3b.3
OR
sympasympaMatch3.3b.4
OR
sympasympaMatch3.4
OR
sympasympaMatch4.0.a1
OR
sympasympaMatch4.0.a3
OR
sympasympaMatch4.0.a4
OR
sympasympaMatch4.0.a5
OR
sympasympaMatch4.0.a6
OR
sympasympaMatch4.0.a7
OR
sympasympaMatch4.0.a8
OR
sympasympaMatch4.0.a9
OR
sympasympaMatch4.0.b1
OR
sympasympaMatch4.0.b2
OR
sympasympaMatch4.0.b3
OR
sympasympaMatch4.1
OR
sympasympaMatch4.2b.1
OR
sympasympaMatch4.2b.3
OR
sympasympaMatch5.0
OR
sympasympaMatch5.0a
OR
sympasympaMatch5.0a.1
OR
sympasympaMatch5.0b
OR
sympasympaMatch5.0b.1
OR
sympasympaMatch5.1
OR
sympasympaMatch5.1.2
OR
sympasympaMatch5.2
OR
sympasympaMatch5.2b
OR
sympasympaMatch5.2b2
OR
sympasympaMatch5.3
OR
sympasympaMatch5.3.2
OR
sympasympaMatch5.3a.8
OR
sympasympaMatch5.3a.9
OR
sympasympaMatch5.3a.10
OR
sympasympaMatch5.3b.1
OR
sympasympaMatch5.3b.3
OR
sympasympaMatch5.3b.4
OR
sympasympaMatch5.3b.5
OR
sympasympaMatch5.4
OR
sympasympaMatch5.4.1
OR
sympasympaMatch5.4.2
OR
sympasympaMatch5.4.3
OR
sympasympaMatch5.4a.2
OR
sympasympaMatch5.4a.4
OR
sympasympaMatch5.4b.1
OR
sympasympaMatch6.0
OR
sympasympaMatch6.0.1
OR
sympasympaMatch6.0.2
OR
sympasympaMatch6.0.3
OR
sympasympaMatch6.0.4
OR
sympasympaMatch6.0.5
OR
sympasympaMatch6.0.6
OR
sympasympaMatch6.0b.1
OR
sympasympaMatch6.0b.2
OR
sympasympaMatch6.0b.3
OR
sympasympaMatch6.0b.4
OR
sympasympaMatch6.1.1
OR
sympasympaMatch6.1.2
OR
sympasympaMatch6.1.3
OR
sympasympaMatch6.1.4
OR
sympasympaMatch6.1.5
OR
sympasympaMatch6.1.6
OR
sympasympaMatch6.1.7
OR
sympasympaMatch6.1.8
OR
sympasympaMatch6.1.9
OR
sympasympaMatch6.1b.1
OR
sympasympaMatch6.1b.2
OR
sympasympaMatch6.1b.3
OR
sympasympaMatch6.1b.4
OR
sympasympaMatch6.1b.6

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.6%