CGI Script Center's Subscribe Me Allows Elevated Privileges

The product does not protect against unauthorized users resetting the administrative password.

ITPro Today

August 22, 2000

1 Min Read
ITPro Today logo in a gray background | ITPro Today

 

Reported August 23, 2000 by n30

VERSIONS AFFECTED

  • CGI Script Center's Subscibe Me - all Lite versions

DESCRIPTION

Administrative level access can be obtained to the product by overwriting the existing admistrator password by calling a specific URL and passing it the new password. 

DEMONSTRATION

The following form (provided by the discoverer) will reset the password to whatever is entered. Note: the form is non-funtional in its current state since no specific URL has been defined in the "action' tag.

 

VENDOR RESPONSE

The problem has been fixed in Subscribe Me Lite version2.0

CREDIT
Discovered by n30

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like