Vulnerability Name:

CVE-2009-4896 (CCN-59755)

Assigned:2010-06-23
Published:2010-06-23
Updated:2010-08-03
Summary:Multiple directory traversal vulnerabilities in the mlmmj-php-admin web interface for Mailing List Managing Made Joyful (mlmmj) 1.2.15 through 1.2.17 allow remote authenticated users to overwrite, create, or delete arbitrary files, or determine the existence of arbitrary directories, via a .. (dot dot) in a list name in a (1) edit or (2) save action.
CVSS v3 Severity:3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
5.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-22
Vulnerability Consequences:Gain Access
References:Source: CONFIRM
Type: UNKNOWN
http://bugs.gentoo.org/show_bug.cgi?id=259968

Source: MITRE
Type: CNA
CVE-2009-4896

Source: CCN
Type: mlmmj Web site
mlmmj

Source: CONFIRM
Type: UNKNOWN
http://mlmmj.org/node/84

Source: SECUNIA
Type: Vendor Advisory
40658

Source: DEBIAN
Type: UNKNOWN
DSA-2073

Source: DEBIAN
Type: DSA-2073
mlmmj -- insufficient input sanitising

Source: MLIST
Type: UNKNOWN
[oss-security] 20100623 CVE Request -- mlmmj -- Directory traversal flaw by editing and saving list entries via php-admin web interface

Source: MLIST
Type: UNKNOWN
[oss-security] 20100623 Re: CVE Request -- mlmmj -- Directory traversal flaw by editing and saving list entries via php-admin web interface

Source: MLIST
Type: UNKNOWN
[oss-security] 20100625 Re: CVE Request -- mlmmj -- Directory traversal flaw by editing and saving list entries via php-admin web interface

Source: MLIST
Type: Patch
[oss-security] 20100626 Re: CVE Request -- mlmmj -- Directory traversal flaw by editing and saving list entries via php-admin web interface

Source: MLIST
Type: UNKNOWN
[oss-security] 20100704 Re: CVE Request -- mlmmj -- Directory traversal flaw by editing and saving list entries via php-admin web interface

Source: MLIST
Type: UNKNOWN
[oss-security] 20100706 Re: CVE Request -- mlmmj -- Directory traversal flaw by editing and saving list entries via php-admin web interface

Source: CCN
Type: OSVDB ID: 66515
mlmmj on Debian Administrative Interface Traversal Arbitrary File Deletion

Source: CCN
Type: BID-41080
mlmmj Edit and Save Multiple Directory Traversal Vulnerabilities

Source: CCN
Type: BID-41841
mlmmj (Mailing List Managing Made Joyful) Directory Traversal Vulnerability

Source: CCN
Type: Red Hat Bugzilla Bug 607256
CVE-2009-4896 mlmmj: Directory traversal flaw by editing and saving list entries via php-admin web interface

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=607256

Source: XF
Type: UNKNOWN
mlmmj-edit-save-dir-traversal(59755)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mlmmj:mlmmj:1.2.15:*:*:*:*:*:*:*
  • OR cpe:/a:mlmmj:mlmmj:1.2.16:*:*:*:*:*:*:*
  • OR cpe:/a:mlmmj:mlmmj:1.2.17:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:mlmmj:mlmmj:1.2.15:*:*:*:*:*:*:*
  • OR cpe:/a:mlmmj:mlmmj:1.2.16:*:*:*:*:*:*:*
  • AND
  • cpe:/o:debian:debian_linux:5.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:11742
    P
    DSA-2073 mlmmj -- insufficient input sanitising
    2014-06-23
    oval:org.mitre.oval:def:13460
    P
    DSA-2073-1 mlmmj -- insufficient input sanitising
    2014-06-23
    oval:com.ubuntu.precise:def:20094896000
    V
    CVE-2009-4896 on Ubuntu 12.04 LTS (precise) - untriaged.
    2010-08-02
    oval:org.debian:def:2073
    V
    insufficient input sanitising
    2010-07-20
    BACK
    mlmmj mlmmj 1.2.15
    mlmmj mlmmj 1.2.16
    mlmmj mlmmj 1.2.17
    mlmmj mlmmj 1.2.15
    mlmmj mlmmj 1.2.16
    debian debian linux 5.0