4.3
CVSSv2

CVE-2005-0842

Published: 02/05/2005 Updated: 18/10/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote malicious users to inject arbitrary web script or HTML via the (1) _i or (2) _c parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

kayako esupport 2.3

Exploits

source: wwwsecurityfocuscom/bid/12868/info Kayako ESupport is prone to a cross-site scripting vulnerability Multiple parameters of the 'indexphp' script can be exploited to pass malicious HTML and script code to the application This would occur in the security context of the affected Web site and may allow for theft of cookie-based a ...