Back

CVE-2005-3679

SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username field in the admin control panel.

Published: Nov 18, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
activecampaign 1-2-all_broadcast_email 4.07

GitHub Security Advisory GHSA-3577-c386-rjj5

SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.27%

Top 33% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub