CVE-2006-1487: XSS
Published Mar 29, 2006
·Updated
Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the KnowledgeBase search module.
Affected Software
1 affected component
ActiveCampaign SupportTrio=2.50.2
Event History
Mar 29, 2006
CVE Published
02:02 AM
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1487?
CVE-2006-1487 is considered a moderate severity vulnerability due to its potential impact on web application security.
2
How do I fix CVE-2006-1487?
To fix CVE-2006-1487, update ActiveCampaign SupportTrio to the latest version that addresses this vulnerability.
3
What types of attacks can be executed due to CVE-2006-1487?
CVE-2006-1487 allows attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
4
Which version of ActiveCampaign SupportTrio is affected by CVE-2006-1487?
ActiveCampaign SupportTrio version 2.50.2 is affected by CVE-2006-1487.
5
What are the consequences of exploiting CVE-2006-1487?
Exploiting CVE-2006-1487 can lead to unauthorized access to sensitive information and user sessions through XSS attacks.