PT-2006-7384 · Unknown · Open Newsletter
Blackhawk
·
Published
2006-12-28
·
Updated
2017-10-19
·
CVE-2006-6785
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Open Newsletter versions 2.5 and earlier
Description:
The issue concerns the settings.php and subscribers.php scripts, which do not properly exit when authentication fails. This allows remote attackers to potentially perform unauthorized administrative actions or execute arbitrary code, especially when combined with another vulnerability.
Recommendations:
For Open Newsletter versions 2.5 and earlier, consider temporarily restricting access to the settings.php and subscribers.php scripts until a proper fix is available. As a mitigation measure, ensure that authentication mechanisms are properly validated and exit the script when authentication fails to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open Newsletter