vendor:
Subscribe Me Lite
by:
teleh0r@doglover.com
7.5
CVSS
HIGH
Remote Password Modification
259
CWE
Product Name: Subscribe Me Lite
Affected Version From: 2
Affected Version To: 2
Patch Exists: NO
Related CWE: N/A
CPE: a:cgiscriptcenter:subscribe_me_lite
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Windows, Mac
2000
Subscribe Me Lite 2.0 exploit
Regardless of privilege level, any remote user can modify the administrative password for CGI Script Centers' Subscribe Me Lite. This would grant the user full administrative privileges which includes addition or removal of users from mailing lists.
Mitigation:
Ensure that the administrative password is strong and secure and that access to the administrative interface is restricted to trusted users.