Total vulnerabilities in the database
The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with a small search space ("lyris" and up to 5 digits, possibly from the process ID), which allows remote attackers to gain access via a brute force attack.
Software | From | Fixed in |
---|---|---|
lyris_technologies_inc / listmanager | 5.0 | 5.0.x |
lyris_technologies_inc / listmanager | 8.0 | 8.0.x |
lyris_technologies_inc / listmanager | 8.8a | 8.8a.x |
lyris_technologies_inc / listmanager | 6.0 | 6.0.x |
lyris_technologies_inc / listmanager | 7.0 | 7.0.x |