CVE Vulnerabilities

CVE-2006-6786

Published: Dec 28, 2006 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php.

Affected Software

NameVendorStart VersionEnd Version
Open_newsletterOpen_newsletter*2.5 (including)
Open_newsletterOpen_newsletter2.0 (including)2.0 (including)

References