MEDIUM
Lyris ListManager 8.95 allows remote authenticated users to obtain sensitive information by attempting to add a user with a ' (single quote) character in the name, which reveals the details of the underlying SQL query, possibly because of a forced SQL error or SQL injection
Published Sep 6, 2006
6.5
MEDIUMCVSS 2.0
EPSS 1.01%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.