Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in s.pl in Subscribe Me Pro 2.044.09P and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Subscribe Me Pro远程目录遍历漏洞
Vulnerability Description
Subscribe Me Pro是一款基于Web的邮件列表管理系统。 Subscribe Me Pro在处理用户请求时存在输入验证漏洞,远程攻击者可能利用此漏洞遍历服务器目录,以Web进程权限访问任意文件。Subscribe Me Pro的s.pl脚本没有充分检查过滤l参数的内容,远程攻击者可以在数据中插入"../../"类似的目录遍历串,从而访问系统上的任意权限。
CVSS Information
N/A
Vulnerability Type
N/A