Kayako ESupport Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
BID:12037
Info
Kayako ESupport Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
| Bugtraq ID: | 12037 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2004 12:00AM |
| Updated: | Dec 18 2004 12:00AM |
| Credit: | Discovery is credited to James Bercegay of the GulfTech Security Research Team. |
| Vulnerable: |
Kayako eSupport 2.3 Kayako eSupport 2.2.5 Kayako eSupport 2.2 Kayako eSupport 2.1.8 Kayako eSupport 2.1.2 |
| Not Vulnerable: | |
Discussion
Kayako ESupport Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
Kayako eSupport is prone to multiple input validation vulnerabilities. One cross-site scripting and six SQL injection vulnerabilities.
These issues may collectively threaten compromise of software and database security properties. Possible attacks include theft of cookie-based authentication credentials, exposure or modification of database information, and a potential for attacks against the underlying database implementation.
Kayako eSupport is prone to multiple input validation vulnerabilities. One cross-site scripting and six SQL injection vulnerabilities.
These issues may collectively threaten compromise of software and database security properties. Possible attacks include theft of cookie-based authentication credentials, exposure or modification of database information, and a potential for attacks against the underlying database implementation.
Exploit / POC
Kayako ESupport Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
The following example demonstrates cross-site scripting:
http://www.example.com/index.php?_a=knowledgebase&_j=search&searchm=[CODEGOESHERE]
The following examples demonstrate SQL injection:
http://www.example.com/index.php?_a=knowledgebase&_j=subcat&_i=[SQL]
http://www.example.com/index.php?_a=knowledgebase&_j=rate&_i=[SQL]&type=no
http://www.example.com/index.php?_a=knowledgebase&_j=questiondetails&_i=[SQL]
http://www.example.com/index.php?_a=tickets&_m=viewmain&email22=blah@blah&ticketkey22=[
SQL]
http://www.example.com/index.php?_a=tickets&_m=viewmain&email22=[SQL]&ticketkey22=
The following example demonstrates cross-site scripting:
http://www.example.com/index.php?_a=knowledgebase&_j=search&searchm=[CODEGOESHERE]
The following examples demonstrate SQL injection:
http://www.example.com/index.php?_a=knowledgebase&_j=subcat&_i=[SQL]
http://www.example.com/index.php?_a=knowledgebase&_j=rate&_i=[SQL]&type=no
http://www.example.com/index.php?_a=knowledgebase&_j=questiondetails&_i=[SQL]
http://www.example.com/index.php?_a=tickets&_m=viewmain&email22=blah@blah&ticketkey22=[
SQL]
http://www.example.com/index.php?_a=tickets&_m=viewmain&email22=[SQL]&ticketkey22=
Solution / Fix
Kayako ESupport Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
Solution:
The researcher who reported this issue stated that a fix was pending from the vendor. This has not been confirmed by Symantec.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The researcher who reported this issue stated that a fix was pending from the vendor. This has not been confirmed by Symantec.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Kayako ESupport Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
References:
References:
- Kayako Homepage (Kayako)
- Multiple Vulnerabilities In Kayako eSupport v2.x ("GulfTech Security"
)