HIGH · 7.5

CVE-2006-6785

The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative acti...

Vulnerability Description

The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Open NewsletterOpen Newsletter<= 2.5

References

FAQ

What is CVE-2006-6785?

CVE-2006-6785 is a vulnerability with a CVSS score of 7.5 (HIGH). The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative acti...

How severe is CVE-2006-6785?

CVE-2006-6785 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-6785?

Check the references section above for vendor advisories and patch information. Affected products include: Open Newsletter Open Newsletter.