CVE-2007-2371 describes a critical vulnerability in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier. This flaw allows unauthenticated remote attackers to access and modify configuration settings via the admin/index.php file before login. The vulnerability carries a CVSS score of 10.0, indicating a severe risk of denial of service through configuration data loss, and potentially direct static code injection, due to its network-based attack vector and low complexity. While no active exploitation is confirmed and it's not on the KEV catalog, an ExploitDB entry exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.8_beta_5CPE matchmatch criteria | cpe:2.3:a:gregory_kokanosky:phpmynewsletter:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.