CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/5735 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2000-12/0160.html | mailing list vendor advisory |
http://www.securityfocus.com/bid/2108 | exploit vdb entry vendor advisory |