The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allows remote attackers to identify the email addresses of members of mailing lists via a "which" command.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:46
Type | Values Removed | Values Added |
---|---|---|
References | () http://securityreason.com/securityalert/3235 - | |
References | () http://www.securityfocus.com/archive/1/310113 - Exploit | |
References | () http://www.securityfocus.com/bid/6761 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/11243 - |
Information
Published : 2003-12-31 05:00
Updated : 2024-11-20 23:46
NVD link : CVE-2003-1367
Mitre link : CVE-2003-1367
CVE.ORG link : CVE-2003-1367
JSON object : View
Products Affected
great_circle_associates
- majordomo
CWE
CWE-16
Configuration