4.3
CVSSv2

CVE-2008-3700

Published: 15/08/2008 Updated: 08/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and previous versions allow remote malicious users to inject arbitrary web script or HTML via (1) the sessionid parameter in a livesupport startclientchat action to visitor/index.php; (2) the filter parameter in a news view action to index.php; or the Full Name field in a (3) account creation, (4) ticket opening, or (5) chat request operation.

Vulnerable Product Search on Vulmon Subscribe to Product

kayako supportsuite 3.10.02

kayako supportsuite 3.11.00

kayako supportsuite 3.10.00

kayako supportsuite 3.11.01

kayako supportsuite

Exploits

source: wwwsecurityfocuscom/bid/30642/info Kayako SupportSuite is prone to multiple input-validation vulnerabilities, including an SQL-injection issue, multiple cross-site scripting issues, and an HTML-injection issue The vulnerabilities occur because the application fails to sufficiently sanitize user-supplied data Exploiting these is ...
source: wwwsecurityfocuscom/bid/30642/info Kayako SupportSuite is prone to multiple input-validation vulnerabilities, including an SQL-injection issue, multiple cross-site scripting issues, and an HTML-injection issue The vulnerabilities occur because the application fails to sufficiently sanitize user-supplied data Exploiting these ...