CVE-2006-0970: High severity activecampaign general vulnerability
PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0970?
CVE-2006-0970 is considered a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2006-0970?
To fix CVE-2006-0970, ensure that the PHP scripts do not allow user input to influence file inclusion paths.
What software is affected by CVE-2006-0970?
CVE-2006-0970 affects various ActiveCampaign products, including ActiveCampaign General, KnowledgeBuilder, Visualedit, and SupportTrio.
Can CVE-2006-0970 be exploited remotely?
Yes, CVE-2006-0970 can be exploited remotely by attackers to include arbitrary files.
What are the potential consequences of CVE-2006-0970 exploitation?
Exploiting CVE-2006-0970 can lead to unauthorized access and control over the server, potentially compromising sensitive data.