5
CVSSv2

CVE-2005-4638

Published: 31/12/2005 Updated: 20/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

index.php in Kayako SupportSuite 3.00.26 and previous versions allow remote malicious users to obtain the full path via (1) _a and (2) newsid parameters in the news module, (3) downloaditemid parameter in the downloads module, and (4) kbarticleid parameter in the knowledgebase module.

Vulnerable Product Search on Vulmon Subscribe to Product

kayako supportsuite