CVE-2005-3557: Medium severity Tincan Phplist vulnerability
Published Nov 16, 2005
·Updated
Directory traversal vulnerability in admin/defaults.php in PHPlist 2.10.1 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) in the selected%5B%5D parameter in an HTTP POST request.
Affected Software
1 affected component
Tincan Phplist<=2.10.1
Remediation
Patch Available
Patch Available
Event History
Nov 16, 2005
CVE Published
07:42 AM
CVE Published
via MITRE·12:37 PM
Data Sourced
via MITRE·12:37 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3557?
CVE-2005-3557 is considered a high-severity vulnerability due to its potential to allow unauthorized access to sensitive files.
2
How do I fix CVE-2005-3557?
To fix CVE-2005-3557, upgrade PHPlist to version 2.10.2 or later which addresses this directory traversal vulnerability.
3
Who is affected by CVE-2005-3557?
CVE-2005-3557 affects users of PHPlist version 2.10.1 and earlier.
4
What kind of attacks can be performed using CVE-2005-3557?
Using CVE-2005-3557, attackers can perform directory traversal attacks to access arbitrary files on the server.
5
When was CVE-2005-3557 reported?
CVE-2005-3557 was reported in 2005, highlighting vulnerabilities in older versions of PHPlist.