Vulnerabilities > CVE-2007-2372 - Scripts Authentication Bypass vulnerability in PHPMyNewsLetter

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
gregory-kokanosky
critical
exploit available

Summary

admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a direct request for the MsgId value under admin/.

Vulnerable Configurations

Part Description Count
Application
Gregory_Kokanosky
1

Exploit-Db

descriptionphpMyNewsletter. CVE-2007-2371,CVE-2007-2372. Webapps exploit for php platform
fileexploits/php/webapps/3671.php
idEDB-ID:3671
last seen2016-01-31
modified2007-04-05
platformphp
port
published2007-04-05
reporterBlackHawk
sourcehttps://www.exploit-db.com/download/3671/
titlephpMyNewsletter <= 0.8 beta5 - Multiple Vulnerability Exploit
typewebapps