Show filters
25 Total Results
Displaying 11-20 of 25
Sort by:
Attacker Value
Unknown

CVE-2008-3700

Disclosure Date: August 15, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the sessionid parameter in a livesupport startclientchat action to visitor/index.php; (2) the filter parameter in a news view action to index.php; or the Full Name field in a (3) account creation, (4) ticket opening, or (5) chat request operation.
0
Attacker Value
Unknown

CVE-2008-0395

Disclosure Date: January 23, 2008 (last updated October 04, 2023)
Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml/index.php, which prints the contents of the $_SERVER superglobal.
0
Attacker Value
Unknown

CVE-2007-2562

Disclosure Date: May 09, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 3.00.90 allows remote attackers to inject arbitrary web script or HTML via the _m parameter.
0
Attacker Value
Unknown

CVE-2007-1145

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a (1) lostpassword or (2) register action in index.php, (3) unspecified vectors in the Submit form in a submit action in index.php, and (4) the user's name in index.php; and (5) allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the Admin and Staff Control Panel. NOTE: this might issue overlap CVE-2004-1412, CVE-2005-0487, or CVE-2005-0842.
0
Attacker Value
Unknown

CVE-2006-5825

Disclosure Date: November 10, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Kayako SupportSuite 3.00.32 allows remote attackers to inject arbitrary web script or HTML via the query string.
0
Attacker Value
Unknown

CVE-2006-4011

Disclosure Date: August 07, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in esupport/admin/autoclose.php in Kayako eSupport 2.3.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the subd parameter.
0
Attacker Value
Unknown

CVE-2005-2463

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Kayako liveResponse 2.x allows remote attackers to obtain sensitive information via a direct request to addressbook.php and other include scripts, which reveals the path in an error message.
0
Attacker Value
Unknown

CVE-2005-4638

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
index.php in Kayako SupportSuite 3.00.26 and earlier allow remote attackers to obtain the full path via (1) _a and (2) newsid parameters in the news module, (3) downloaditemid parameter in the downloads module, and (4) kbarticleid parameter in the knowledgebase module.
0
Attacker Value
Unknown

CVE-2005-2462

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Kayako liveResponse 2.x, when logging in a user, records the password in plaintext in the URL, which allows local users and possibly remote attackers to gain privileges.
0
Attacker Value
Unknown

CVE-2005-2460

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Kayako liveResponse 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter or (2) name field when entering a session or sending a message.
0