CVE-2012-6554

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
23/05/2013
Last modified:
11/04/2025

Description

functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP code via the message[message_text] parameter to chat/add_messag, which is not properly handled when executing the preg_replace function with the eval switch.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:a51dev:activecollab_chat_module:1.0:*:*:*:*:*:*:*
cpe:2.3:a:a51dev:activecollab_chat_module:1.1:*:*:*:*:*:*:*
cpe:2.3:a:a51dev:activecollab_chat_module:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:a51dev:activecollab_chat_module:1.2:*:*:*:*:*:*:*
cpe:2.3:a:a51dev:activecollab_chat_module:1.3:*:*:*:*:*:*:*
cpe:2.3:a:a51dev:activecollab_chat_module:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:a51dev:activecollab_chat_module:1.4:*:*:*:*:*:*:*
cpe:2.3:a:a51dev:activecollab_chat_module:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:a51dev:activecollab_chat_module:1.5:*:*:*:*:*:*:*
cpe:2.3:a:a51dev:activecollab_chat_module:1.5.1:*:*:*:*:*:*:*