First published: Fri Mar 03 2006(Updated: )
PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ActiveCampaign | ||
ActiveCampaign KnowledgeBuilder | ||
ActiveCampaign Visualedit | ||
ActiveCampaign | ||
ActiveCampaign 1-2-All Broadcast Email | ||
ActiveCampaign SupportTrio |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0970 is considered a high severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2006-0970, ensure that the PHP scripts do not allow user input to influence file inclusion paths.
CVE-2006-0970 affects various ActiveCampaign products, including ActiveCampaign General, KnowledgeBuilder, Visualedit, and SupportTrio.
Yes, CVE-2006-0970 can be exploited remotely by attackers to include arbitrary files.
Exploiting CVE-2006-0970 can lead to unauthorized access and control over the server, potentially compromising sensitive data.