The TCLHTTPd service in Lyris ListManager before 8.9b allows remote attackers to obtain source code for arbitrary .tml (TCL) files via (1) a request with a trailing null byte (%00), which might also require (2) an authentication bypass step that involves a username with a trailing @ characters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Listmanager | Lyris_technologies_inc | 5.0 (including) | 5.0 (including) |
Listmanager | Lyris_technologies_inc | 6.0 (including) | 6.0 (including) |
Listmanager | Lyris_technologies_inc | 7.0 (including) | 7.0 (including) |
Listmanager | Lyris_technologies_inc | 8.0 (including) | 8.0 (including) |
Listmanager | Lyris_technologies_inc | 8.8a (including) | 8.8a (including) |