Back

CVE-2006-0970

PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter.

Published: Mar 3, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
activecampaign 1-2-all *
activecampaign general *
activecampaign isalient *
activecampaign knowledgebuilder *
activecampaign supporttrio *
activecampaign visualedit *

GitHub Security Advisory GHSA-8fqw-3pg3-gmfj

PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products,...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.54%

Top 27% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub