CVE-2006-6786 EXPLOIT
6.5
MEDIUM · CVSS 2.0 · EPSS 1.9% (pctl 79)
Patch early
A public exploit exists.
Description
Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php.
Scoring
| CVSS | 6.5 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
| EPSS | 1.88% — more likely to be exploited than 79% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-12-28 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| open newsletter | open newsletter |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | open NewsLetter 2.5 - Multiple Vulnerabilities (2) | 2006-12-23 |
References
→ the Explorer · watch your stack · NVD