|
|
| |
| Subscribe Me is a powerful mailing list manager that allows you to build your prospect/customer mailing list completely hands-free. A vulnerability in the product allows remote attackers to unsubscribe anyone they want from the list by only knowing their email. |
| |
Credit:
The information has been provided by Digital Vampire.
|
| |
Vulnerable systems:
Subscribe Me Lite v2.01
Immune systems:
Subscribe Me Professional version 2.034 Beta 5
Subscribe Me Professional version 2.039
It seems you can delete anyone from the subscription database with a simple web browser URL call in the form of:
http://www.example.com/cgi-bin/subscribe.pl?victims@email.com
This allows you to remove anyone without knowing the administrative password.
|
|
|
|
|
|
|
|