CVE-2005-3679: SQL Injection
SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username field in the admin control panel.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3679?
CVE-2005-3679 is classified as a high severity SQL injection vulnerability that permits remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2005-3679?
To remediate CVE-2005-3679, it is recommended to upgrade to a patched version of ActiveCampaign 1-2-All Broadcast Email or validate and sanitize user input in the application.
What software is affected by CVE-2005-3679?
CVE-2005-3679 specifically affects ActiveCampaign 1-2-All Broadcast Email version 4.07.
Can CVE-2005-3679 lead to unauthorized access?
Yes, CVE-2005-3679 can allow attackers to bypass authentication and gain unauthorized access to the admin panel.
Is CVE-2005-3679 being actively exploited?
While specific exploit activity for CVE-2005-3679 may vary, the nature of SQL injection vulnerabilities makes them a common target for attackers.