The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with a small search space (lyris and up to 5 digits, possibly from the process ID), which allows remote attackers to gain access via a brute force attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Listmanager | Lyris_technologies_inc | 5.0 (including) | 5.0 (including) |
Listmanager | Lyris_technologies_inc | 6.0 (including) | 6.0 (including) |
Listmanager | Lyris_technologies_inc | 7.0 (including) | 7.0 (including) |
Listmanager | Lyris_technologies_inc | 8.0 (including) | 8.0 (including) |
Listmanager | Lyris_technologies_inc | 8.8a (including) | 8.8a (including) |