CVE-2006-0920 describes a vulnerability in Oi! Email Marketing System 3.0 where the server's FTP password is stored in cleartext on a configuration web page. This allows local users with superadministrator privileges, or attackers gaining access to this page, to view the password. The vulnerability has a low CVSS score of 1.7, indicating a local attack vector, low attack complexity, and a potential impact of only partial confidentiality. There is no evidence of active exploitation, no Metasploit or Nuclei modules, and minimal community discussion or media coverage, though an unrelated SQL injection exploit for the same product exists on ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:oi:email_marketing_system:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:S/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.