CVE

CVE-2006-6785

Severity:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/12/2006
Last modified:
19/10/2017

Description

The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:open_newsletter:open_newsletter:*:*:*:*:*:*:*:* 2.5 (including)
cpe:2.3:a:open_newsletter:open_newsletter:2.0:*:*:*:*:*:*:*