7.5
CVSSv2

CVE-2005-3679

Published: 18/11/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote malicious users to execute arbitrary SQL commands and bypass authentication via the username field in the admin control panel.

Vulnerable Product Search on Vulmon Subscribe to Product

activecampaign 1-2-all broadcast email 4.07

Exploits

source: wwwsecurityfocuscom/bid/15400/info ActiveCampaign 1-2-All Broadcast Email is prone to an SQL-injection vulnerability This is an input-validation issue related to data that will be used in SQL queries, allowing a remote user to influence the structure and logic of a query Successful attacks could compromise the software Dependi ...