PT-2004-2328 · Kayako · Kayako Esupport

James Bercegay

·

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-1413

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Kayako eSupport versions 2.x
Description: The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via several parameters to index.php, including subcat, rate, questiondetails, ticketkey22, email22, or the e-mail field of the Forgot Key feature.
Recommendations: For Kayako eSupport version 2.x, consider restricting access to the vulnerable parameters subcat, rate, questiondetails, ticketkey22, email22 in the index.php file until a patch is available. Additionally, limit the use of the e-mail field in the Forgot Key feature to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1413

Affected Products

Kayako Esupport