Back

CVE-2005-4142

The web interface for subscribing new users in Lyris ListManager 5.0 through 8.8b, in combination with a line wrap feature, allows remote attackers to execute arbitrary list administration commands via LFCR (%0A%0D) sequences in the pw parameter. NOTE: it is not clear whether this is a variant of a CRLF injection vulnerability.

Published: Dec 10, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
lyris_technologies_inc listmanager 5.0
lyris_technologies_inc listmanager 6.0
lyris_technologies_inc listmanager 7.0
lyris_technologies_inc listmanager 8.0
lyris_technologies_inc listmanager 8.8a

GitHub Security Advisory GHSA-8prw-qcgj-xjrj

The web interface for subscribing new users in Lyris ListManager 5.0 through 8.8b, in combination...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.01%

Top 14% most likely to be exploited

Threat Score 30.9 / 100

Data Sources

NVD EPSS GitHub