Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Scorpion

#36098of 53,624
7.5Total CVSS
Vulnerabilities · 1
PT-2010-4400
7.5
2010-07-28
Kayako · Kayako Esupport · CVE-2010-2912
**Name of the Vulnerable Software and Affected Versions** Kayako eSupport version 3.70.02 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the ` a` parameter in a `downloads` action within the `index.php` file. **Recommendations** For Kayako eSupport version 3.70.02, consider restricting access to the `index.php` file until a patch is available, and avoid using the ` a` parameter in the `downloads` action to minimize the risk of exploitation.