6.5
CVE-2006-6786
- EPSS 1.72%
- Veröffentlicht 28.12.2006 00:28:00
- Zuletzt bearbeitet 16.06.2026 22:33:47
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Open Newsletter ≫ Open Newsletter Version <= 2.5
Open Newsletter ≫ Open Newsletter Version2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.72% | 0.746 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
http://www.securityfocus.com/bid/21775
https://www.exploit-db.com/exploits/2981