Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-6785

Опубликовано: 28 дек. 2006
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:open_newsletter:open_newsletter:*:*:*:*:*:*:*:*
Версия до 2.5 (включая)
cpe:2.3:a:open_newsletter:open_newsletter:2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 90%
0.04186
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 4 лет назад

The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.

EPSS

Процентиль: 90%
0.04186
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other