CVE-2008-5055
ActiveCampaign TrioLive < 1.58.7 - SQL Injection via department_id Parameter
Title source: llmDescription
SQL injection vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to execute arbitrary SQL commands via the department_id parameter to index.php.
References (7)
Core 7
Core References
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3125
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/32268
Patch x_refsource_confirm
http://activecampaign.com/support/forum/showthread.php?t=4554
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/32703
Various Sources x_refsource_misc
http://holisticinfosec.org/content/view/93/45/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/49825
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46557
Scores
EPSS
0.0131
EPSS Percentile
67.7%
Details
CWE
CWE-89
Status
published
Products (50)
activecampaign/triolive
1.0
activecampaign/triolive
1.03
activecampaign/triolive
1.04
activecampaign/triolive
1.05
activecampaign/triolive
1.06
activecampaign/triolive
1.07
activecampaign/triolive
1.08
activecampaign/triolive
1.09
activecampaign/triolive
1.10
activecampaign/triolive
1.11
... and 40 more
Published
Nov 13, 2008
Tracked Since
Feb 18, 2026