CVE-2006-6785 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 4.3% (pctl 91)
Patch early
A public exploit exists.
Description
The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 4.35% — more likely to be exploited than 91% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-12-28 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| open newsletter | open newsletter |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | open NewsLetter 2.5 - Multiple Vulnerabilities (2) | 2006-12-23 |
References
→ the Explorer · watch your stack · NVD