Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Lyris ListManager 5.0 through 8.9a allows remote attackers to add "ORDER BY" columns to SQL queries via unusual whitespace characters in the orderby parameter, such as (1) newlines and (2) 0xFF (ASCII 255) characters, which are interpreted as whitespace.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Lyris Listmanager多个SQL注入漏洞
Vulnerability Description
AOL Lyris ListManager(LM)是美国在线(AOL)公司的一套用于管理邮件列表,创建邮件、新闻组和讨论组的电子邮件营销软件。 ListManager中用于读取消息附件的函数中存在SQL注入漏洞,远程攻击者可能利用此漏洞在主机上执行任意命令。 攻击者可以通过请求以下URL对后端数据库执行任意命令: /read/attachment/1;DELETE+FROM+TABLENAME;--/3 此外,orderby参数中也存在多个SQL注入漏洞。攻击者可以向web界面中所显示大部分项提供SQL
CVSS Information
N/A
Vulnerability Type
N/A