Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-6785

Опубликовано: 28 дек. 2006
Источник: nvd
CVSS2: 7.5
EPSS Средний

Описание

The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:open_newsletter:open_newsletter:*:*:*:*:*:*:*:*
Версия до 2.5 (включая)
cpe:2.3:a:open_newsletter:open_newsletter:2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 96%
0.26385
Средний

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.

EPSS

Процентиль: 96%
0.26385
Средний

7.5 High

CVSS2

Дефекты

NVD-CWE-Other