SupportTrio search cross-site scripting

supporttrio-search-xss (25495) The risk level is classified as MediumMedium Risk

Description:

SupportTrio from ActiveCampaign is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the Knowledgebase search module. A remote attacker could exploit this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site, allowing the attacker to steal the victim's cookie-based authentication credentials.


Consequences:

Gain Access

Remedy:

Upgrade to the latest version of SupportTrio (2.50.18 or later), available from the SupportTrio Web site. See References.

References:

  • SupportTrioWeb site: ActiveCampaign, Inc. - Web Based PHP/MySQL Help Desk Script.
  • UNSECURED SYSTEMS 28 march 2006: ActiveCampaign SupportTrio 2.5 vuln. .
  • BID-17276: ActiveCampaign SupportTrio Multiple Cross-Site Scripting Vulnerabilities
  • CVE-2006-1487: Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the KnowledgeBase search module.
  • OSVDB ID: 24192: ActiveCampaign SupportTrio Search Module terms Variable XSS
  • SA19431: ActiveCampaign SupportTrio "terms" Cross-Site Scripting
  • VUPEN/ADV-2006-1126: ActiveCampaign SupportTrio Cross Site Scripting and Path Disclosure Vulnerabilities

Platforms Affected:

  • ActiveCampaign SupportTrio 2.50.2

Reported:

Mar 28, 2006

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page