Bug: phpList vulnerability (WLB-2008120033 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: phpList vulnerability
 Credit: phplist
 Date: 2008.12.16
 CWE: CWE-20 (Show similar)
 CVE: CVE-2008-5887 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Medium
No
Yes

phpList is a feature rich newsletter application written in PHP.

phpList has a local file include vulnerability. The vulnerability has
already been exploited.

affected versions: any version up to including 2.10.7

fixed in version 2.10.8

Related links:
www.phplist.com phpList homepage
http://sourceforge.net/projects/phplist Sourceforge Project page.

References:

http://www.securityfocus.com/bid/32841
http://www.securityfocus.com/archive/1/archive/1/499218/100/0/threaded
http://www.phplist.com/?lid=273
http://secunia.com/advisories/33186

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com