CVE Database
/

CVE-2007-2372

Back to search

CVE-2007-2372

Published: Apr 30, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a direct request for the MsgId value under admin/.

VendorProductVersions

n/a

n/a

affected
n/a

References

23342
vdb-entry
x_refsource_BID
3671
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now