Title: BulletScript MailList bsml.pl Information Disclosure Vulnerability
Severity: MODERATE
Description:
BulletScript MailList is a cgi script used to handle mailing lists.
A vulnerability has been reported to exist in the software that may allow remote attackers to gain access to sensitive information. The issue is reported to be present in the bsml.pl script. An attacker may be able to disclose sensitive information by gaining unauthorized access to the script. Successful attacks may allow an attacker to gain access to the control panel and/or the subscribers of a mailing list by passing arbitrary values to the 'action' parameter. Information gathered via these attacks may aid an attacker in mounting further attacks against a vulnerable system and the affected users.
Due to a lack of information, further details cannot be outlined at the moment. This BID will be updated as more information becomes available.
Affected Products:
- BulletScript MailList 0.0.0
References:
- BulletScript: MailList
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.