CVE-2012-2352

EUVD-2012-2345
The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers to list, read, and delete arbitrary list archives via vectors related to the (1) do_arc_manage, (2) do_arc_download, or (3) do_arc_delete functions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
Affected Products (NVD)
VendorProductVersion
sympasympa
𝑥
≤ 6.1.10
sympasympa
0.001
sympasympa
0.002
sympasympa
0.003
sympasympa
0.004
sympasympa
0.005
sympasympa
0.006
sympasympa
0.007
sympasympa
0.008
sympasympa
0.009
sympasympa
0.010
sympasympa
0.011
sympasympa
1.2.0
sympasympa
1.2.1
sympasympa
1.2.2
sympasympa
1.3.0
sympasympa
1.3.1
sympasympa
1.3.1-2
sympasympa
1.3.2
sympasympa
1.3.3
sympasympa
1.3.4
sympasympa
1.3.4-1
sympasympa
1.4.0
sympasympa
1.4.1
sympasympa
1.4.2
sympasympa
1.4.2-1
sympasympa
1.5
sympasympa
2.2.1b:b
sympasympa
2.2.2b:b
sympasympa
2.2.3b:b
sympasympa
2.2.4
sympasympa
2.2.5
sympasympa
2.2.6
sympasympa
2.2.7
sympasympa
2.2b:b
sympasympa
2.3:beta
sympasympa
2.3.0
sympasympa
2.3.1
sympasympa
2.3.2
sympasympa
2.3.3
sympasympa
2.3.4
sympasympa
2.4
sympasympa
2.5
sympasympa
2.5.1
sympasympa
2.5.2
sympasympa
2.5.3b:b
sympasympa
2.5.4b:b
sympasympa
2.6
sympasympa
2.6.1
sympasympa
2.7
sympasympa
2.7.1
sympasympa
2.7.2
sympasympa
2.7.3
sympasympa
2.7a:a
sympasympa
2.7b.1:b.1
sympasympa
2.7b.2:b.2
sympasympa
2.7b.3:b.3
sympasympa
3.0
sympasympa
3.0a:a
sympasympa
3.0a.1:a.1
sympasympa
3.0b.4:b.4
sympasympa
3.0b.8:b.8
sympasympa
3.0b.9:b.9
sympasympa
3.1
sympasympa
3.1.1
sympasympa
3.1b.7:b.7
sympasympa
3.1b.8:b.8
sympasympa
3.1b.9:b.9
sympasympa
3.1b.10:b.10
sympasympa
3.1b.12:b.12
sympasympa
3.1b.13:b.13
sympasympa
3.2
sympasympa
3.2.1
sympasympa
3.2.2a:a
sympasympa
3.3
sympasympa
3.3.1
sympasympa
3.3.3
sympasympa
3.3.4b.3:b.3
sympasympa
3.3.4b.4:b.4
sympasympa
3.3.4b.5:b.5
sympasympa
3.3.4b.6:b.6
sympasympa
3.3.4b.7:b.7
sympasympa
3.3.4b.8:b.8
sympasympa
3.3.4b.9:b.9
sympasympa
3.3.5
sympasympa
3.3.6b.1:b.1
sympasympa
3.3.6b.2:b.2
sympasympa
3.3.6b.3:b.3
sympasympa
3.3.6b.4:b.4
sympasympa
3.3.6b.5:b.5
sympasympa
3.3.6b.6:b.6
sympasympa
3.3b.3:b.3
sympasympa
3.3b.4:b.4
sympasympa
3.4
sympasympa
4.0.a1:a1
sympasympa
4.0.a3:a3
sympasympa
4.0.a4:a4
sympasympa
4.0.a5:a5
sympasympa
4.0.a6:a6
sympasympa
4.0.a7:a7
sympasympa
4.0.a8:a8
sympasympa
4.0.a9:a9
sympasympa
4.0.b1:b1
sympasympa
4.0.b2:b2
sympasympa
4.0.b3:b3
sympasympa
4.1
sympasympa
4.2b.1:b.1
sympasympa
4.2b.3:b.3
sympasympa
5.0
sympasympa
5.0a:a
sympasympa
5.0a.1:a.1
sympasympa
5.0b:b
sympasympa
5.0b.1:b.1
sympasympa
5.1
sympasympa
5.1.2
sympasympa
5.2
sympasympa
5.2b:b
sympasympa
5.2b2:b2
sympasympa
5.3
sympasympa
5.3.2
sympasympa
5.3a.8:a.8
sympasympa
5.3a.9:a.9
sympasympa
5.3a.10:a.10
sympasympa
5.3b.1:b.1
sympasympa
5.3b.3:b.3
sympasympa
5.3b.4:b.4
sympasympa
5.3b.5:b.5
sympasympa
5.4
sympasympa
5.4.1
sympasympa
5.4.2
sympasympa
5.4.3
sympasympa
5.4a.2:a.2
sympasympa
5.4a.4:a.4
sympasympa
5.4b.1:b.1
sympasympa
6.0
sympasympa
6.0.1
sympasympa
6.0.2
sympasympa
6.0.3
sympasympa
6.0.4
sympasympa
6.0.5
sympasympa
6.0.6
sympasympa
6.0b.1:b.1
sympasympa
6.0b.2:b.2
sympasympa
6.0b.3:b.3
sympasympa
6.0b.4:b.4
sympasympa
6.1.1
sympasympa
6.1.2
sympasympa
6.1.3
sympasympa
6.1.4
sympasympa
6.1.5
sympasympa
6.1.6
sympasympa
6.1.7
sympasympa
6.1.8
sympasympa
6.1.9
sympasympa
6.1b.1:b.1
sympasympa
6.1b.2:b.2
sympasympa
6.1b.3:b.3
sympasympa
6.1b.4:b.4
sympasympa
6.1b.6:b.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
sympa
bookworm
6.2.70~dfsg-2
fixed
bullseye
6.2.60~dfsg-4
fixed
sid
6.2.72~dfsg-1
fixed
trixie
6.2.72~dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sympa
hardy
ignored
lucid
ignored
natty
ignored
oneiric
ignored
precise
ignored
quantal
ignored
raring
ignored
saucy
ignored
trusty
dne
utopic
not-affected
vivid
not-affected
wily
not-affected
xenial
not-affected
yakkety
not-affected
zesty
not-affected
Common Weakness Enumeration