7.5
CVE-2006-6785
- EPSS 4.16%
- Veröffentlicht 28.12.2006 00:28:00
- Zuletzt bearbeitet 16.06.2026 22:33:47
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Open Newsletter ≫ Open Newsletter Version <= 2.5
Open Newsletter ≫ Open Newsletter Version2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.16% | 0.896 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/23476
http://www.securityfocus.com/bid/21775
https://www.exploit-db.com/exploits/2981