7.5
CVSSv2

CVE-2006-6785

Published: 28/12/2006 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and previous versions do not exit when authentication fails, which allows remote malicious users to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

open newsletter open newsletter 2.0

open newsletter open newsletter

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? echo "\r\n"; echo "Open Newsletter <= 2* Muliple Vulnerabilities\r\n"; echo "Site: wwwselfexilecom/projects/opennewsletter/\r\n"; echo "Dork: \"This is a Free & Open Source mailing list manager\"\r\n"; echo "by BlackHawk <hawkgotyou@gmailcom> <itablackhawkaltervistaorg ...