CVE-2009-4896

Publication date 2 August 2010

Last updated 17 July 2025


Ubuntu priority

Description

Multiple directory traversal vulnerabilities in the mlmmj-php-admin web interface for Mailing List Managing Made Joyful (mlmmj) 1.2.15 through 1.2.17 allow remote authenticated users to overwrite, create, or delete arbitrary files, or determine the existence of arbitrary directories, via a .. (dot dot) in a list name in a (1) edit or (2) save action.

Status

Package Ubuntu Release Status
mlmmj 13.10 saucy
Not affected
13.04 raring
Not affected
12.10 quantal
Not affected
12.04 LTS precise
Not affected
11.10 oneiric
Not affected
11.04 natty
Not affected
10.10 maverick
Not affected
10.04 LTS lucid Ignored end of life
9.10 karmic
Fixed 1.2.15-1.1+lenny1build0.9.10.1
9.04 jaunty
Fixed 1.2.15-1.1+lenny1build0.9.04.1
8.04 LTS hardy Ignored end of life
6.06 LTS dapper
Not affected


Access our resources on patching vulnerabilities