Kayako Fusion 'download.php' Cross Site Scripting Vulnerability
BID:55417
Info
Kayako Fusion 'download.php' Cross Site Scripting Vulnerability
| Bugtraq ID: | 55417 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-3233 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2012 12:00AM |
| Updated: | Sep 05 2012 12:00AM |
| Credit: | High-Tech Bridge Security Research Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Kayako Fusion 'download.php' Cross Site Scripting Vulnerability
Kayako Fusion is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Kayako Fusion 4.40.1148 is vulnerable; other versions may also be affected.
Kayako Fusion is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Kayako Fusion 4.40.1148 is vulnerable; other versions may also be affected.
Exploit / POC
Kayako Fusion 'download.php' Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
The following example URI is available:
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
The following example URI is available:
Solution / Fix
Kayako Fusion 'download.php' Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Kayako Fusion 'download.php' Cross Site Scripting Vulnerability
References:
References:
- Kayako Fusion Homepage (kayako)
- Cross-Site Scripting (XSS) in Kayako Fusion (High-Tech Bridge SA)
- High-Tech Bridge Advisory HTB23095 (High-Tech Bridge SA)