CVE-2008-5055

ActiveCampaign TrioLive < 1.58.7 - SQL Injection via department_id Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to execute arbitrary SQL commands via the department_id parameter to index.php.

References (7)

Core 7
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3125
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32268
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32703
Various Sources x_refsource_misc
http://holisticinfosec.org/content/view/93/45/
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/49825
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46557

Scores

EPSS 0.0131
EPSS Percentile 67.7%

Details

CWE
CWE-89
Status published
Products (50)
activecampaign/triolive 1.0
activecampaign/triolive 1.03
activecampaign/triolive 1.04
activecampaign/triolive 1.05
activecampaign/triolive 1.06
activecampaign/triolive 1.07
activecampaign/triolive 1.08
activecampaign/triolive 1.09
activecampaign/triolive 1.10
activecampaign/triolive 1.11
... and 40 more
Published Nov 13, 2008
Tracked Since Feb 18, 2026