Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
kayako supportsuite vulnerabilities and exploits
(subscribe to this query)
312
VMScore
CVE-2010-0460
Multiple cross-site scripting (XSS) vulnerabilities in staff/index.php in Kayako SupportSuite 3.60.04 and previous versions allow remote authenticated users to inject arbitrary web script or HTML via the (1) subject parameter and (2) contents parameter (aka body) in an insertques...
Kayako Supportsuite 3.11.00
Kayako Supportsuite 3.10.02
Kayako Supportsuite 3.30
Kayako Supportsuite 3.00.26
Kayako Supportsuite 3.0
Kayako Esupport
Kayako Supportsuite 3.50.06
Kayako Supportsuite 3.10.00
Kayako Supportsuite 3.00.32
Kayako Supportsuite 3.20.02
Kayako Supportsuite 3.11.01
655
VMScore
CVE-2008-3701
SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and previous versions allows remote authenticated users to execute arbitrary SQL commands via the customfieldlinkid parameter in a delcflink action.
Kayako Supportsuite 3.10.00
Kayako Supportsuite 3.11.01
Kayako Supportsuite
Kayako Supportsuite 3.10.02
Kayako Supportsuite 3.11.00
1 EDB exploit
440
VMScore
CVE-2008-3700
Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and previous versions allow remote malicious users to inject arbitrary web script or HTML via (1) the sessionid parameter in a livesupport startclientchat action to visitor/index.php; (2) the filte...
Kayako Supportsuite 3.10.02
Kayako Supportsuite 3.11.00
Kayako Supportsuite 3.10.00
Kayako Supportsuite 3.11.01
Kayako Supportsuite
2 EDB exploits
383
VMScore
CVE-2009-3567
Cross-site scripting (XSS) vulnerability in modules/tickets/functions_ticketsui.php in Kayako SupportSuite and eSupport 3.60.04 and previous versions allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors in the staff control panel, a differe...
Kayako Esupport 2.2.5
Kayako Esupport 2.3
Kayako Esupport 2.1.8
Kayako Supportsuite 3.10.02
Kayako Esupport 2.3.1
Kayako Esupport 3.00.13
Kayako Supportsuite 3.11.00
Kayako Supportsuite 3.00.26
Kayako Supportsuite 3.10.00
Kayako Esupport 3.04.10
Kayako Esupport 3.00.90
Kayako Supportsuite 3.20.02
Kayako Supportsuite 3.00.32
Kayako Esupport
Kayako Supportsuite
Kayako Esupport 2.2
Kayako Esupport 2.1.2
Kayako Supportsuite 3.11.01
Kayako Supportsuite 3.50.06
445
VMScore
CVE-2005-4638
index.php in Kayako SupportSuite 3.00.26 and previous versions allow remote malicious users to obtain the full path via (1) _a and (2) newsid parameters in the news module, (3) downloaditemid parameter in the downloads module, and (4) kbarticleid parameter in the knowledgebase mo...
Kayako Supportsuite
383
VMScore
CVE-2009-3427
Cross-site scripting (XSS) vulnerability in Kayako SupportSuite 3.50.06 allows remote malicious users to inject arbitrary web script or HTML via the subject field in a ticket.
Kayako Supportsuite 3.50.06
445
VMScore
CVE-2008-0395
Kayako SupportSuite 3.11.01 allows remote malicious users to obtain server configuration information via a direct request to syncml/index.php, which prints the contents of the $_SERVER superglobal.
Kayako Supportsuite 3.11.01
435
VMScore
CVE-2006-5825
Cross-site scripting (XSS) vulnerability in index.php in Kayako SupportSuite 3.00.32 allows remote malicious users to inject arbitrary web script or HTML via the query string.
Kayako Supportsuite 3.00.32
1 EDB exploit
383
VMScore
CVE-2007-1145
Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors related to a (1) lostpassword or (2) register action in index.php, (3) unspecified...
Kayako Esupport 3.00.13
Kayako Esupport 3.04.10
435
VMScore
CVE-2005-4637
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kayako SupportSuite 3.00.26 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) nav parameter in the downloads module, (2) Full Name and (3) Email fields in the c...
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started