ActiveCampaign 1-2-All Broadcast Email Admin Control Panel Username SQL Injection Vulnerability
BID:15400
CVE-2005-3679 |Info
ActiveCampaign 1-2-All Broadcast Email Admin Control Panel Username SQL Injection Vulnerability
| Bugtraq ID: | 15400 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3679 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2005 12:00AM |
| Updated: | Mar 17 2010 07:24PM |
| Credit: | Discovery is credited to [email protected]. |
| Vulnerable: |
ActiveCampaign 1-2-All Broadcast Email 4.0 7 |
| Not Vulnerable: |
ActiveCampaign 1-2-All Broadcast Email 4.08 |
Discussion
ActiveCampaign 1-2-All Broadcast Email Admin Control Panel Username SQL Injection Vulnerability
ActiveCampaign 1-2-All Broadcast Email is prone to an SQL-injection vulnerability. This is an input-validation issue related to data that will be used in SQL queries, allowing a remote user to influence the structure and logic of a query.
Successful attacks could compromise the software. Depending on the database implementation and the nature of the affected query, the attacker may be able to gain unauthorized access to the database.
ActiveCampaign 1-2-All Broadcast Email is prone to an SQL-injection vulnerability. This is an input-validation issue related to data that will be used in SQL queries, allowing a remote user to influence the structure and logic of a query.
Successful attacks could compromise the software. Depending on the database implementation and the nature of the affected query, the attacker may be able to gain unauthorized access to the database.
Exploit / POC
ActiveCampaign 1-2-All Broadcast Email Admin Control Panel Username SQL Injection Vulnerability
The following example was provided:
http://www.example.com/[12allTarget]/admin/index.php
Username: ' or 1=1 /*
Password: (Nothing)(Blank)
The following example was provided:
http://www.example.com/[12allTarget]/admin/index.php
Username: ' or 1=1 /*
Password: (Nothing)(Blank)
Solution / Fix
ActiveCampaign 1-2-All Broadcast Email Admin Control Panel Username SQL Injection Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
ActiveCampaign 1-2-All Broadcast Email Admin Control Panel Username SQL Injection Vulnerability
References:
References: