← Back

CVE-2012-2352

nvd nist
Published: May 31, 2012Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers to list, read, and delete arbitrary list archives via vectors related to the (1) do_arc_manage, (2) do_arc_download, or (3) do_arc_delete functions.

Affected (159)

Products: Sympa: Sympa
1 product
Sympa
Configuration A
159 vulnerable
Vulnerable SoftwareAffected Versions
Sympa
Up to 6.1.10
Version 0.001
Version 0.002
Version 0.003
Version 0.004
Version 0.005
Version 0.006
Version 0.007
Version 0.008
Version 0.009
Version 0.010
Version 0.011
Version 1.2.0
Version 1.2.1
Version 1.2.2
Version 1.3.0
Version 1.3.1-2
Version 1.3.1
Version 1.3.2
Version 1.3.3
Version 1.3.4-1
Version 1.3.4
Version 1.4.0
Version 1.4.1
Version 1.4.2-1
Version 1.4.2
Version 1.5
Version 2.2.1b
Version 2.2.2b
Version 2.2.3b
Version 2.2.4
Version 2.2.5
Version 2.2.6
Version 2.2.7
Version 2.2b
Version 2.3.0
Version 2.3.1
Version 2.3.2
Version 2.3.3
Version 2.3.4
Version 2.3 beta
Version 2.4
Version 2.5.1
Version 2.5.2
Version 2.5.3b
Version 2.5.4b
Version 2.5
Version 2.6.1
Version 2.6
Version 2.7.1
Version 2.7.2
Version 2.7.3
Version 2.7
Version 2.7a
Version 2.7b.1
Version 2.7b.2
Version 2.7b.3
Version 3.0
Version 3.0a.1
Version 3.0a
Version 3.0b.4
Version 3.0b.8
Version 3.0b.9
Version 3.1.1
Version 3.1
Version 3.1b.10
Version 3.1b.12
Version 3.1b.13
Version 3.1b.7
Version 3.1b.8
Version 3.1b.9
Version 3.2.1
Version 3.2.2a
Version 3.2
Version 3.3.1
Version 3.3.3
Version 3.3.4b.3
Version 3.3.4b.4
Version 3.3.4b.5
Version 3.3.4b.6
Version 3.3.4b.7
Version 3.3.4b.8
Version 3.3.4b.9
Version 3.3.5
Version 3.3.6b.1
Version 3.3.6b.2
Version 3.3.6b.3
Version 3.3.6b.4
Version 3.3.6b.5
Version 3.3.6b.6
Version 3.3
Version 3.3b.3
Version 3.3b.4
Version 3.4
Version 4.0.a1
Version 4.0.a3
Version 4.0.a4
Version 4.0.a5
Version 4.0.a6
Version 4.0.a7
Version 4.0.a8
Version 4.0.a9
Version 4.0.b1
Version 4.0.b2
Version 4.0.b3
Version 4.1
Version 4.2b.1
Version 4.2b.3
Version 5.0
Version 5.0a.1
Version 5.0a
Version 5.0b.1
Version 5.0b
Version 5.1.2
Version 5.1
Version 5.2
Version 5.2b2
Version 5.2b
Version 5.3.2
Version 5.3
Version 5.3a.10
Version 5.3a.8
Version 5.3a.9
Version 5.3b.1
Version 5.3b.3
Version 5.3b.4
Version 5.3b.5
Version 5.4.1
Version 5.4.2
Version 5.4.3
Version 5.4
Version 5.4a.2
Version 5.4a.4
Version 5.4b.1
Version 6.0.1
Version 6.0.2
Version 6.0.3
Version 6.0.4
Version 6.0.5
Version 6.0.6
Version 6.0
Version 6.0b.1
Version 6.0b.2
Version 6.0b.3
Version 6.0b.4
Version 6.1.1
Version 6.1.2
Version 6.1.3
Version 6.1.4
Version 6.1.5
Version 6.1.6
Version 6.1.7
Version 6.1.8
Version 6.1.9
Version 6.1b.1
Version 6.1b.2
Version 6.1b.3
Version 6.1b.4
Version 6.1b.6

Related CWEs

References (20)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.