Subscribe Me Pro 2.044.09P and prior Directory Traversal Vulnerability
SEVERITY:
=========
High
SOFTWARE:
=========
Subscribe Me Pro 2.044.09P and prior
Support Website : http://siteinteractive.com/subpro/
INFO:
=====
Subscribe Me Professional is designed to assist with the building,
maintaining, mailing, and tracking of your customer/prospect mailing
lists.
BUG DESCRIPTION:
================
Subscribe Me Pro 2.044.09P and prior are prone to a directory traversal
vulnerability. This issue is due to a failure in the application to
properly sanitize user-supplied input. An unauthorized user can retrieve
arbitrary files by supplying directory traversal strings '../' to the
vulnerable parameter.
--
http://www.h4cky0u.org
(In)Security at its best...
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Microsoft Device IO Control wrapped by the iphlpapi.dll API shipping with Windows Vista 32 bit and 64 bit contains a possibly exploitable, buffer overflow corrupting kernel memory.