Subscribe Me Pro 2.044.09P and prior Directory Traversal Vulnerability
SEVERITY:
=========
High
SOFTWARE:
=========
Subscribe Me Pro 2.044.09P and prior
Support Website : http://siteinteractive.com/subpro/
INFO:
=====
Subscribe Me Professional is designed to assist with the building,
maintaining, mailing, and tracking of your customer/prospect mailing
lists.
BUG DESCRIPTION:
================
Subscribe Me Pro 2.044.09P and prior are prone to a directory traversal
vulnerability. This issue is due to a failure in the application to
properly sanitize user-supplied input. An unauthorized user can retrieve
arbitrary files by supplying directory traversal strings '../' to the
vulnerable parameter.
--
http://www.h4cky0u.org
(In)Security at its best...
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.