Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:23
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/21775 - Exploit | |
References | () https://www.exploit-db.com/exploits/2981 - |
Information
Published : 2006-12-28 00:28
Updated : 2024-11-21 00:23
NVD link : CVE-2006-6786
Mitre link : CVE-2006-6786
CVE.ORG link : CVE-2006-6786
JSON object : View
Products Affected
open_newsletter
- open_newsletter
CWE