← Vulnerability feed

Vulnerability record · CVE-2005-3557 · published 16 November 2005

CVE-2005-3557: Tincan phplist vulnerability

Tincan · Phplist

Directory traversal vulnerability in admin/defaults.php in PHPlist 2.10.1 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) in the selected%5B%5D parameter in an HTTP POST request.

5.0 CVSS 2.0 Medium EPSS 2.2% · top 18.2%
5.0CVSS 2.0 base score
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in admin/defaults.php in PHPlist 2.10.1 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) in the selected%5B%5D parameter in an HTTP POST request.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-3557 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2009-0422Tincan phplist code injection vulnerabilityDynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attacker…EPSS 6.2%7.5CVE-2006-5322Tincan phplist vulnerabilityMultiple SQL injection vulnerabilities in phplist before 2.10.3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.EPSS 1.2%7.5CVE-2005-2432Tincan phplist vulnerabilitySQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2)…EPSS 1.3%6.8CVE-2011-0748Tincan phplist cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administr…EPSS 1.5%6.5CVE-2005-3555Tincan phplist vulnerabilityMultiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administrator privileges to execute ar…EPSS 1.6%5.0CVE-2008-5887Tincan phplist improper input validation vulnerabilityphplist before 2.10.8 allows remote attackers to include files via unknown vectors, related to a "local file include vulnerability."EPSS 11%5.0CVE-2006-1746Tincan phplist path traversal vulnerabilityDirectory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers to include arbitrary local files via the (1) GLOBALS[database…EPSS 2.4%5.0CVE-2005-2433Tincan phplist vulnerabilityPhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) us…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2005-3557), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.