PT-2007-7417 · Nmn · Nmnnewsletter

Cracker

·

Published

2007-12-28

·

Updated

2017-09-29

·

CVE-2007-6585

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NmnNewsletter version 1.0.7
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the output parameter in the confirmUnsubscription.php file.
Recommendations For NmnNewsletter version 1.0.7, consider disabling the confirmUnsubscription.php file or restricting access to it until a patch is available. Avoid using the output parameter in the affected file to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6585

Affected Products

Nmnnewsletter