CVE detail
CVE-2005-4142 — CVE-2005-4142
Published 2005-12-10 · Modified 2026-06-16 · Vendor lyris_technologies_inc · Product listmanager · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0301
EPSS probability
exploitation probability, 30d
86.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The web interface for subscribing new users in Lyris ListManager 5.0 through 8.8b, in combination with a line wrap feature, allows remote attackers to execute arbitrary list administration commands via LFCR (%0A%0D) sequences in the pw parameter. NOTE: it is not clear whether this is a variant of a CRLF injection vulnerability.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References