Unrated severityNVD Advisory· Published Dec 10, 2005· Updated Apr 16, 2026
CVE-2005-4147
CVE-2005-4147
Description
The TCLHTTPd service in Lyris ListManager before 8.9b allows remote attackers to obtain source code for arbitrary .tml (TCL) files via (1) a request with a trailing null byte (%00), which might also require (2) an authentication bypass step that involves a username with a trailing "@" characters.
Affected products
5cpe:2.3:a:lyris_technologies_inc:listmanager:5.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:lyris_technologies_inc:listmanager:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:lyris_technologies_inc:listmanager:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:lyris_technologies_inc:listmanager:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:lyris_technologies_inc:listmanager:8.0:*:*:*:*:*:*:*
- cpe:2.3:a:lyris_technologies_inc:listmanager:8.8a:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.securityfocus.com/bid/15788nvdPatch
- metasploit.com/research/vulns/lyris_listmanager/nvdExploitPatch
- secunia.com/advisories/17943nvdExploitPatchVendor Advisory
- www.osvdb.org/21551nvdExploitPatch
- www.osvdb.org/21573nvdExploitPatch
- archives.neohapsis.com/archives/fulldisclosure/2005-12/0349.htmlnvd
- www.securityfocus.com/archive/1/419077/100/0/threadednvd
- www.vupen.com/english/advisories/2005/2820nvd
News mentions
0No linked articles in our index yet.