CVE-2003-1367

The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allows remote attackers to identify the email addresses of members of mailing lists via a "which" command.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:great_circle_associates:majordomo:*:*:*:*:*:*:*:*
cpe:2.3:a:great_circle_associates:majordomo:1.94.4:*:*:*:*:*:*:*
cpe:2.3:a:great_circle_associates:majordomo:1.94.5:*:*:*:*:*:*:*

History

20 Nov 2024, 23:46

Type Values Removed Values Added
References () http://securityreason.com/securityalert/3235 - () http://securityreason.com/securityalert/3235 -
References () http://www.securityfocus.com/archive/1/310113 - Exploit () http://www.securityfocus.com/archive/1/310113 - Exploit
References () http://www.securityfocus.com/bid/6761 - () http://www.securityfocus.com/bid/6761 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/11243 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/11243 -

Information

Published : 2003-12-31 05:00

Updated : 2024-11-20 23:46


NVD link : CVE-2003-1367

Mitre link : CVE-2003-1367

CVE.ORG link : CVE-2003-1367


JSON object : View

Products Affected

great_circle_associates

  • majordomo
CWE
CWE-16

Configuration