CVE-2012-2352

The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers to list, read, and delete arbitrary list archives via vectors related to the (1) do_arc_manage, (2) do_arc_download, or (3) do_arc_delete functions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
sympasympa
𝑥
≤ 6.1.10
sympasympa
0.001
sympasympa
0.002
sympasympa
0.003
sympasympa
0.004
sympasympa
0.005
sympasympa
0.006
sympasympa
0.007
sympasympa
0.008
sympasympa
0.009
sympasympa
0.010
sympasympa
0.011
sympasympa
1.2.0
sympasympa
1.2.1
sympasympa
1.2.2
sympasympa
1.3.0
sympasympa
1.3.1
sympasympa
1.3.1-2
sympasympa
1.3.2
sympasympa
1.3.3
sympasympa
1.3.4
sympasympa
1.3.4-1
sympasympa
1.4.0
sympasympa
1.4.1
sympasympa
1.4.2
sympasympa
1.4.2-1
sympasympa
1.5
sympasympa
2.2.1b:b
sympasympa
2.2.2b:b
sympasympa
2.2.3b:b
sympasympa
2.2.4
sympasympa
2.2.5
sympasympa
2.2.6
sympasympa
2.2.7
sympasympa
2.2b:b
sympasympa
2.3:beta
sympasympa
2.3.0
sympasympa
2.3.1
sympasympa
2.3.2
sympasympa
2.3.3
sympasympa
2.3.4
sympasympa
2.4
sympasympa
2.5
sympasympa
2.5.1
sympasympa
2.5.2
sympasympa
2.5.3b:b
sympasympa
2.5.4b:b
sympasympa
2.6
sympasympa
2.6.1
sympasympa
2.7
sympasympa
2.7.1
sympasympa
2.7.2
sympasympa
2.7.3
sympasympa
2.7a:a
sympasympa
2.7b.1:b.1
sympasympa
2.7b.2:b.2
sympasympa
2.7b.3:b.3
sympasympa
3.0
sympasympa
3.0a:a
sympasympa
3.0a.1:a.1
sympasympa
3.0b.4:b.4
sympasympa
3.0b.8:b.8
sympasympa
3.0b.9:b.9
sympasympa
3.1
sympasympa
3.1.1
sympasympa
3.1b.7:b.7
sympasympa
3.1b.8:b.8
sympasympa
3.1b.9:b.9
sympasympa
3.1b.10:b.10
sympasympa
3.1b.12:b.12
sympasympa
3.1b.13:b.13
sympasympa
3.2
sympasympa
3.2.1
sympasympa
3.2.2a:a
sympasympa
3.3
sympasympa
3.3.1
sympasympa
3.3.3
sympasympa
3.3.4b.3:b.3
sympasympa
3.3.4b.4:b.4
sympasympa
3.3.4b.5:b.5
sympasympa
3.3.4b.6:b.6
sympasympa
3.3.4b.7:b.7
sympasympa
3.3.4b.8:b.8
sympasympa
3.3.4b.9:b.9
sympasympa
3.3.5
sympasympa
3.3.6b.1:b.1
sympasympa
3.3.6b.2:b.2
sympasympa
3.3.6b.3:b.3
sympasympa
3.3.6b.4:b.4
sympasympa
3.3.6b.5:b.5
sympasympa
3.3.6b.6:b.6
sympasympa
3.3b.3:b.3
sympasympa
3.3b.4:b.4
sympasympa
3.4
sympasympa
4.0.a1:a1
sympasympa
4.0.a3:a3
sympasympa
4.0.a4:a4
sympasympa
4.0.a5:a5
sympasympa
4.0.a6:a6
sympasympa
4.0.a7:a7
sympasympa
4.0.a8:a8
sympasympa
4.0.a9:a9
sympasympa
4.0.b1:b1
sympasympa
4.0.b2:b2
sympasympa
4.0.b3:b3
sympasympa
4.1
sympasympa
4.2b.1:b.1
sympasympa
4.2b.3:b.3
sympasympa
5.0
sympasympa
5.0a:a
sympasympa
5.0a.1:a.1
sympasympa
5.0b:b
sympasympa
5.0b.1:b.1
sympasympa
5.1
sympasympa
5.1.2
sympasympa
5.2
sympasympa
5.2b:b
sympasympa
5.2b2:b2
sympasympa
5.3
sympasympa
5.3.2
sympasympa
5.3a.8:a.8
sympasympa
5.3a.9:a.9
sympasympa
5.3a.10:a.10
sympasympa
5.3b.1:b.1
sympasympa
5.3b.3:b.3
sympasympa
5.3b.4:b.4
sympasympa
5.3b.5:b.5
sympasympa
5.4
sympasympa
5.4.1
sympasympa
5.4.2
sympasympa
5.4.3
sympasympa
5.4a.2:a.2
sympasympa
5.4a.4:a.4
sympasympa
5.4b.1:b.1
sympasympa
6.0
sympasympa
6.0.1
sympasympa
6.0.2
sympasympa
6.0.3
sympasympa
6.0.4
sympasympa
6.0.5
sympasympa
6.0.6
sympasympa
6.0b.1:b.1
sympasympa
6.0b.2:b.2
sympasympa
6.0b.3:b.3
sympasympa
6.0b.4:b.4
sympasympa
6.1.1
sympasympa
6.1.2
sympasympa
6.1.3
sympasympa
6.1.4
sympasympa
6.1.5
sympasympa
6.1.6
sympasympa
6.1.7
sympasympa
6.1.8
sympasympa
6.1.9
sympasympa
6.1b.1:b.1
sympasympa
6.1b.2:b.2
sympasympa
6.1b.3:b.3
sympasympa
6.1b.4:b.4
sympasympa
6.1b.6:b.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
sympa
bullseye
6.2.60~dfsg-4
fixed
bookworm
6.2.70~dfsg-2
fixed
sid
6.2.72~dfsg-1
fixed
trixie
6.2.72~dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sympa
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
oneiric
ignored
natty
ignored
lucid
ignored
hardy
ignored
Common Weakness Enumeration