The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2006-12-28 00:28
Updated : 2024-02-04 17:13
NVD link : CVE-2006-6785
Mitre link : CVE-2006-6785
CVE.ORG link : CVE-2006-6785
JSON object : View
Products Affected
open_newsletter
- open_newsletter
CWE