Title: Lyris ListManager TCLHTTPd Status Module Information Disclosure
Info
Disclosure
Dec 08, 2005
Discovery
Jun 21, 2005
Dates
Exploit
Dec 08, 2005
Solution
Unknown
Description
Lyris ListManager contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker requests the /status/ module, which will disclose server configuration information resulting in a loss of confidentiality.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Public
Disclosure:
OSVDB Verified
OSVDB:
Web Related
Solution
Upgrade to version 8.9b or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.