RULE(RULE ID:331331)

Rule General Information
Release Date: 2020-11-18
Rule Name: Active Collab chat module Remote PHP Code Injection Exploit Vulnerability (CVE-2012-6554)
Severity:
CVE ID:
Rule Protection Details
Description: functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP code via the message[message_text] parameter to chat/add_messag, which is not properly handled when executing the preg_replace function with the eval switch.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Android, Others
Reference: ExploitDB:18898
http://www.activecollab.com/downloads/category/4/package/62/releases
SecurityFocusBID:53624
https://exchange.xforce.ibmcloud.com/vulnerabilities/75741
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.activecollab.com/downloads/category/4/package/62/releases