{"api_version":"1","generated_at":"2026-07-23T10:50:37+00:00","cve":"CVE-2006-6785","urls":{"html":"https://cve.report/CVE-2006-6785","api":"https://cve.report/api/cve/CVE-2006-6785.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-6785","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-6785"},"summary":{"title":"CVE-2006-6785","description":"The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-12-28 00:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://www.exploit-db.com/exploits/2981","name":"https://www.exploit-db.com/exploits/2981","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"open NewsLetter 2.5 - Multiple Vulnerabilities (2) - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/21775","name":"http://www.securityfocus.com/bid/21775","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Open Newsletter Settings.PHP Authentication Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/23476","name":"http://secunia.com/advisories/23476","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"OpenNewsletter Security Bypass Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-6785","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-6785","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"6785","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"open_newsletter","cpe5":"open_newsletter","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6785","vulnerable":"1","versionEndIncluding":"2.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"open_newsletter","cpe5":"open_newsletter","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:42:06.589Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"2981","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/2981"},{"name":"23476","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23476"},{"name":"21775","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/21775"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-12-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"2981","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/2981"},{"name":"23476","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23476"},{"name":"21775","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/21775"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-6785","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"2981","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/2981"},{"name":"23476","refsource":"SECUNIA","url":"http://secunia.com/advisories/23476"},{"name":"21775","refsource":"BID","url":"http://www.securityfocus.com/bid/21775"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-6785","datePublished":"2006-12-28T00:00:00.000Z","dateReserved":"2006-12-27T00:00:00.000Z","dateUpdated":"2024-08-07T20:42:06.589Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-12-28 00:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:open_newsletter:open_newsletter:*:*:*:*:*:*:*:*","versionEndIncluding":"2.5","matchCriteriaId":"F62158FA-3A2E-483F-A037-5846A40BE9DB"},{"vulnerable":true,"criteria":"cpe:2.3:a:open_newsletter:open_newsletter:2.0:*:*:*:*:*:*:*","matchCriteriaId":"AECC88D1-1290-46B9-BCC4-CD070B7486D0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"6785","Ordinal":"1","Title":"CVE-2006-6785","CVE":"CVE-2006-6785","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"6785","Ordinal":"1","NoteData":"The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.","Type":"Description","Title":"CVE-2006-6785"},{"CveYear":"2006","CveId":"6785","Ordinal":"2","NoteData":"2006-12-27","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"6785","Ordinal":"3","NoteData":"2017-10-18","Type":"Other","Title":"Modified"}]}}}