CVE Vulnerabilities

CVE-2006-6786

Published: Dec 28, 2006 | Modified: Oct 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php.

Affected Software

Name Vendor Start Version End Version
Open_newsletter Open_newsletter * 2.5 (including)
Open_newsletter Open_newsletter 2.0 (including) 2.0 (including)

References