Lyris List Manager Allows Unauthorized Administrative Access

A particular Lyris List Manager form can be stored locally, modified, and then used to connect to the administrative interface.

ITPro Today

August 17, 2000

1 Min Read
ITPro Today logo

 

Reported August 11, 2000 by Adam Hupp

VERSIONS AFFECTED

  • Lyris List Manager 3.0 and 4.0

DESCRIPTION

After logging in to the Lyris Web interface, a user a presented with a Web page that can be saved, modified in a particular manner, and the transmitted back to the server to gain administrative level access to the product.

DEMONSTRATION

Locate the HTML form field that reads:

and change that VALUE definition to "T" as seen below:

Submit the form to the Web server to gain administrator access

VENDOR RESPONSE

Lyris has released a patch that corrects this matter for versions 3.0 and 4.0.

CREDIT
Discovered by Adam Hupp

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like