2.6
CVSSv2

CVE-2006-4011

Published: 07/08/2006 Updated: 19/10/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 265
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

PHP remote file inclusion vulnerability in esupport/admin/autoclose.php in Kayako eSupport 2.3.1 and previous versions, when register_globals is enabled, allows remote malicious users to execute arbitrary PHP code via a URL in the subd parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

kayako esupport 2.3

kayako esupport 2.3.1

Exploits

Script: Kayako eSupport <= 231 Vendor: Kayako (wwwkayakocom) Discovered: beford <xbefordx gmail com> Comments: It seems like the vendor silently fixed the issue in the current version (more like since v235) withouth warning users of previous versions, noobs Requires that "register_globals" is enabled Vulnerable File: esupport/admin ...