CVE-2012-2352 - CVE House
Back to Database
Status published High CVE-2012-2352

The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before...

Vulnerability Description

The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers to list, read, and delete arbitrary list archives via vectors related to the (1) do_arc_manage, (2) do_arc_download, or (3) do_arc_delete functions.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-2352

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

sympa
Vulnerable Versions:
0, 0.001, 0.002, 0.003, 0.004, 0.005, 0.006, 0.007, 0.008, 0.009, 0.010, 0.011, 1.2.0, 1.2.1, 1.2.2, 1.3.0, 1.3.1, 1.3.1-2, 1.3.2, 1.3.3, 1.3.4, 1.3.4-1, 1.4.0, 1.4.1, 1.4.2, 1.4.2-1, 1.5, 2.2.1b, 2.2.2b, 2.2.3b, 2.2.4, 2.2.5, 2.2.6, 2.2.7, 2.2b, 2.3, 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.4, 2.5, 2.5.1, 2.5.2, 2.5.3b, 2.5.4b, 2.6, 2.6.1, 2.7, 2.7.1, 2.7.2, 2.7.3, 2.7a, 2.7b.1, 2.7b.2, 2.7b.3, 3.0, 3.0a, 3.0a.1, 3.0b.4, 3.0b.8, 3.0b.9, 3.1, 3.1.1, 3.1b.7, 3.1b.8, 3.1b.9, 3.1b.10, 3.1b.12, 3.1b.13, 3.2, 3.2.1, 3.2.2a, 3.3, 3.3.1, 3.3.3, 3.3.4b.3, 3.3.4b.4, 3.3.4b.5, 3.3.4b.6, 3.3.4b.7, 3.3.4b.8, 3.3.4b.9, 3.3.5, 3.3.6b.1, 3.3.6b.2, 3.3.6b.3, 3.3.6b.4, 3.3.6b.5, 3.3.6b.6, 3.3b.3, 3.3b.4, 3.4, 4.0.a1, 4.0.a3, 4.0.a4, 4.0.a5, 4.0.a6, 4.0.a7, 4.0.a8, 4.0.a9, 4.0.b1, 4.0.b2, 4.0.b3, 4.1, 4.2b.1, 4.2b.3, 5.0, 5.0a, 5.0a.1, 5.0b, 5.0b.1, 5.1, 5.1.2, 5.2, 5.2b, 5.2b2, 5.3, 5.3.2, 5.3a.8, 5.3a.9, 5.3a.10, 5.3b.1, 5.3b.3, 5.3b.4, 5.3b.5, 5.4, 5.4.1, 5.4.2, 5.4.3, 5.4a.2, 5.4a.4, 5.4b.1, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0b.1, 6.0b.2, 6.0b.3, 6.0b.4, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1b.1, 6.1b.2, 6.1b.3, 6.1b.4, 6.1b.6

Timeline

Official Publish: May 31st, 2012
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.