CVE-2005-4145
Lyris ListManager <8.9b - Info Disclosure
Title source: llmDescription
The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with a small search space ("lyris" and up to 5 digits, possibly from the process ID), which allows remote attackers to gain access via a brute force attack.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16397
metasploit
WORKING POC
EXCELLENT
by hdm · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/mssql/lyris_listmanager_weak_pass.rb
References (6)
Scores
EPSS
0.6483
EPSS Percentile
98.5%
Details
Status
published
Products (5)
lyris_technologies_inc/listmanager
5.0
lyris_technologies_inc/listmanager
6.0
lyris_technologies_inc/listmanager
7.0
lyris_technologies_inc/listmanager
8.0
lyris_technologies_inc/listmanager
8.8a
Published
Dec 10, 2005
Tracked Since
Feb 18, 2026