First published: Sat Dec 31 2005(Updated: )
SQL injection vulnerability in index.php in ActiveCampaign SupportTrio 1.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the provenance of this information is unknown because the source URL is not available; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ActiveCampaign SupportTrio | =1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4634 has a medium severity rating due to its SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
To fix CVE-2005-4634, it's recommended to upgrade ActiveCampaign SupportTrio to a patched version or implement input validation to sanitize the 'page' parameter.
CVE-2005-4634 specifically affects ActiveCampaign SupportTrio version 1.4.
CVE-2005-4634 is a SQL injection vulnerability that allows attackers to manipulate SQL queries.
Yes, CVE-2005-4634 can be exploited remotely, allowing attackers to execute arbitrary SQL commands on the affected system.