about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Kayako ESupport Index.PHP Multiple Parameter Cross-Site Scripting Vulnerability


Title Kayako ESupport Index.PHP Multiple Parameter Cross-Site Scripting Vulnerability
Published 2005-03-22-12:00AM
Updated 2005-03-22-05:26PM
Class Input Validation Error
CVE   CAN-2005-0842
Remote  Yes
Local  No
Credit  Discovery is credited to James Bercegay of the GulfTech Security Research Team.
Vulnerable  Kayako eSupport 2.3
Not Vulnerable  
Code   An exploit is not required.

The following proof of concept examples are available:

http://www.example.com/index.php?_a=knowledgebase&_j=questiondetails&_i=[INT][XSS]

http://www.example.com/index.php?_a=knowledgebase&_j=questionprint&_i=[INT][XSS]

http://www.example.com/index.php?_a=troubleshooter&_c=[INT][XSS]

http://www.example.com/index.php?_a=knowledgebase&_j=subcat&_i=[INT][XSS]

where [INT] is a valid integer value.
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 01:06:48 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
phoking se Www.saex.c www.80845. www.caipia JENIFER LO narmatha youtube.ro monsters c narmatha www.stardo news for c Apache 1.3 Sexcy ram horde 3 news for C Toenda collegegir minisql www.india www.trish rondo kemp mud girl forbiddenp xxxvido wh0 news for c IceWarp We Street+fig www.Virtua com_flyspr One.lt Apache htt news for c Apache htt videos of Cartoonfre www.katrin message lo Apache htt Apache htt sexmovie.c www.sixmov Anaksekola www.katrin Videos Apache Tom backdoor xxxvidao Gce nov/de spambot