The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-12-27 16:28
Updated : 2017-10-18 18:29
NVD link : CVE-2006-6785
Mitre link : CVE-2006-6785
JSON object : View
CWE
Products Affected
open_newsletter
- open_newsletter