First published: Thu Nov 13 2008(Updated: )
Cross-site scripting (XSS) vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to inject arbitrary web script or HTML via the department_id parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ActiveCampaign TrioLive | =1.31 | |
ActiveCampaign TrioLive | =1.50.1 | |
ActiveCampaign TrioLive | =1.19 | |
ActiveCampaign TrioLive | =1.33 | |
ActiveCampaign TrioLive | =1.05 | |
ActiveCampaign TrioLive | =unknown-beta3 | |
ActiveCampaign TrioLive | =1.06 | |
ActiveCampaign TrioLive | =1.56.2 | |
ActiveCampaign TrioLive | =1.39 | |
ActiveCampaign TrioLive | =1.13 | |
ActiveCampaign TrioLive | =1.58.1 | |
ActiveCampaign TrioLive | =1.30 | |
ActiveCampaign TrioLive | =1.09 | |
ActiveCampaign TrioLive | =1.18 | |
ActiveCampaign TrioLive | =1.56.5 | |
ActiveCampaign TrioLive | =1.16 | |
ActiveCampaign TrioLive | =1.58.3 | |
ActiveCampaign TrioLive | =1.23 | |
ActiveCampaign TrioLive | =1.24 | |
ActiveCampaign TrioLive | =1.57 | |
ActiveCampaign TrioLive | =1.0 | |
ActiveCampaign TrioLive | =unknown-beta5 | |
ActiveCampaign TrioLive | =1.27 | |
ActiveCampaign TrioLive | =1.50.5 | |
ActiveCampaign TrioLive | =1.58.4 | |
ActiveCampaign TrioLive | =1.11 | |
ActiveCampaign TrioLive | =1.36 | |
ActiveCampaign TrioLive | =1.41 | |
ActiveCampaign TrioLive | =1.56.1 | |
ActiveCampaign TrioLive | =1.32 | |
ActiveCampaign TrioLive | =1.10 | |
ActiveCampaign TrioLive | =1.20 | |
ActiveCampaign TrioLive | =1.12 | |
ActiveCampaign TrioLive | =1.22 | |
ActiveCampaign TrioLive | =1.17 | |
ActiveCampaign TrioLive | =1.58.0 | |
ActiveCampaign TrioLive | =1.08 | |
ActiveCampaign TrioLive | =1.56.4 | |
ActiveCampaign TrioLive | =1.55.2 | |
ActiveCampaign TrioLive | =1.55.0 | |
ActiveCampaign TrioLive | =1.50.6 | |
ActiveCampaign TrioLive | =1.03 | |
ActiveCampaign TrioLive | =1.50.2 | |
ActiveCampaign TrioLive | =1.26 | |
ActiveCampaign TrioLive | =1.37 | |
ActiveCampaign TrioLive | =1.29 | |
ActiveCampaign TrioLive | =1.42 | |
ActiveCampaign TrioLive | <=1.58.6 | |
ActiveCampaign TrioLive | =1.25 | |
ActiveCampaign TrioLive | =1.50.4 | |
ActiveCampaign TrioLive | =1.28 | |
ActiveCampaign TrioLive | =1.21 | |
ActiveCampaign TrioLive | =1.35 | |
ActiveCampaign TrioLive | =1.58.5 | |
ActiveCampaign TrioLive | =1.04 | |
ActiveCampaign TrioLive | =1.40 | |
ActiveCampaign TrioLive | =1.55.1 | |
ActiveCampaign TrioLive | =1.50.3 | |
ActiveCampaign TrioLive | =1.56.3 | |
ActiveCampaign TrioLive | =1.07 | |
ActiveCampaign TrioLive | =unknown-beta2 | |
ActiveCampaign TrioLive | =1.58.2 | |
ActiveCampaign TrioLive | =1.34 | |
ActiveCampaign TrioLive | =1.15 | |
ActiveCampaign TrioLive | =1.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5056 is classified as a medium-severity vulnerability due to its potential for exploitation through cross-site scripting.
To fix CVE-2008-5056, update ActiveCampaign TrioLive to version 1.58.7 or later, which contains the patch for this vulnerability.
CVE-2008-5056 affects various versions of ActiveCampaign TrioLive including 1.31, 1.50.1, and several others up to 1.58.6.
An attacker can exploit CVE-2008-5056 to perform a cross-site scripting (XSS) attack, allowing for potential information theft or session hijacking.
Yes, CVE-2008-5056 can be exploited relatively easily through the manipulation of the department_id parameter in index.php.