6.5
CVSSv2

CVE-2006-6786

Published: 28/12/2006 Updated: 19/10/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Open Newsletter 2.5 and previous versions allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php.

Vulnerable Product Search on Vulmon Subscribe to Product

open newsletter open newsletter

open newsletter open newsletter 2.0

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? echo "\r\n"; echo "Open Newsletter <= 2* Muliple Vulnerabilities\r\n"; echo "Site: wwwselfexilecom/projects/opennewsletter/\r\n"; echo "Dork: \"This is a Free & Open Source mailing list manager\"\r\n"; echo "by BlackHawk <hawkgotyou@gmailcom> <itablackhawkaltervistaorg ...