PT-2006-2496 · Activecampaign · Activecampaign Supporttrio

Published

2006-03-29

·

Updated

2017-07-20

·

CVE-2006-1488

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: ActiveCampaign SupportTrio version 2.5
Description: The issue allows remote attackers to obtain the full path of the server. This can be achieved through invalid parameters in specific actions: (1) article or (2) print parameters in a kb action to "index.php", or (3) an invalid category parameter to "modules/KB/pdf.php". The path is leaked in an error message.
Recommendations: For ActiveCampaign SupportTrio version 2.5, consider restricting access to the "index.php" and "modules/KB/pdf.php" files until a patch is available. As a temporary workaround, avoid using invalid article, print, or category parameters in the respective actions to minimize the risk of path leakage.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1488

Affected Products

Activecampaign Supporttrio