CGI Script Center's Subscribe Me Allows Elevated Privileges
The product does not protect against unauthorized users resetting the administrative password.
ITPro Today
August 22, 2000
1 Min Read
Reported August 23, 2000 by n30
VERSIONS AFFECTED
CGI Script Center's Subscibe Me - all Lite versions
DESCRIPTION
Administrative level access can be obtained to the product by overwriting the existing admistrator password by calling a specific URL and passing it the new password.
DEMONSTRATION
The following form (provided by the discoverer) will reset the password to whatever is entered. Note: the form is non-funtional in its current state since no specific URL has been defined in the "action' tag.
VENDOR RESPONSE
The problem has been fixed in Subscribe Me Lite version2.0
CREDIT
Discovered by n30
About the Author
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.
You May Also Like