6.4
CVSSv2

CVE-2005-2461

Published: 31/12/2005 Updated: 18/10/2016
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Multiple SQL injection vulnerabilities in the calendar feature in Kayako liveResponse 2.x allow remote malicious users to execute arbitrary SQL commands via the (1) year or (2) date parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

kayako liveresponse 2.0

Exploits

source: wwwsecurityfocuscom/bid/14425/info Kayako LiveResponse is prone to multiple cross-site scripting, SQL injection, and HTML injection vulnerabilties These issues are all related to input validation errors The cross-site scripting and HTML injection vulnerabilities may allow for theft of cookie-based authentication credentials o ...