Vulnerability Description
The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open Newsletter | Open Newsletter | <= 2.5 |
References
- http://secunia.com/advisories/23476
- http://www.securityfocus.com/bid/21775Exploit
- https://www.exploit-db.com/exploits/2981
- http://secunia.com/advisories/23476
- http://www.securityfocus.com/bid/21775Exploit
- https://www.exploit-db.com/exploits/2981
FAQ
What is CVE-2006-6785?
CVE-2006-6785 is a vulnerability with a CVSS score of 7.5 (HIGH). The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative acti...
How severe is CVE-2006-6785?
CVE-2006-6785 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-6785?
Check the references section above for vendor advisories and patch information. Affected products include: Open Newsletter Open Newsletter.