PoC Index

CVE-2007-2371

HIGH 10.0EPSS 8.0%

admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct static code injection, via a saveGlobalconfig action.

CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
8.04% chance of exploitation in the next 30 days, 94th percentile
Published
2007-04-30
Updated
2024-08-07

ExploitDB entries (1)

References

Related