ActiveCampaign TrioLive 'department_id' SQL Injection and Cross Site Scripting Vulnerabilities
BID:32268
Info
ActiveCampaign TrioLive 'department_id' SQL Injection and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 32268 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5055 CVE-2008-5056 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2008 12:00AM |
| Updated: | Nov 17 2008 08:04PM |
| Credit: | Russ McRee from HolisticInfoSec |
| Vulnerable: |
ActiveCampaign TrioLive 1.58.6 |
| Not Vulnerable: |
ActiveCampaign TrioLive 1.58.7 |
Discussion
ActiveCampaign TrioLive 'department_id' SQL Injection and Cross Site Scripting Vulnerabilities
ActiveCampaign TrioLive is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to TrioLive 1.58.7 are vulnerable.
ActiveCampaign TrioLive is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to TrioLive 1.58.7 are vulnerable.
Exploit / POC
ActiveCampaign TrioLive 'department_id' SQL Injection and Cross Site Scripting Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
ActiveCampaign TrioLive 'department_id' SQL Injection and Cross Site Scripting Vulnerabilities
Solution:
The vendor has released TrioLive 1.58.7 to address these issues. Please see the references for more information.
Solution:
The vendor has released TrioLive 1.58.7 to address these issues. Please see the references for more information.
References
ActiveCampaign TrioLive 'department_id' SQL Injection and Cross Site Scripting Vulnerabilities
References:
References:
- HIO-2008-1110 ActiveCampaign TrioLive SQLi & XSS (HolisticInfoSec)
- TrioLive 1.58.7 Released (ActiveCampaign)
- TrioLive Homepage (ActiveCampaign)