First published: Fri Nov 18 2005(Updated: )
SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username field in the admin control panel.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ActiveCampaign 1-2-All Broadcast Email | =4.07 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3679 is classified as a high severity SQL injection vulnerability that permits remote attackers to execute arbitrary SQL commands.
To remediate CVE-2005-3679, it is recommended to upgrade to a patched version of ActiveCampaign 1-2-All Broadcast Email or validate and sanitize user input in the application.
CVE-2005-3679 specifically affects ActiveCampaign 1-2-All Broadcast Email version 4.07.
Yes, CVE-2005-3679 can allow attackers to bypass authentication and gain unauthorized access to the admin panel.
While specific exploit activity for CVE-2005-3679 may vary, the nature of SQL injection vulnerabilities makes them a common target for attackers.