6.5
CVSSv2

CVE-2008-3701

Published: 15/08/2008 Updated: 08/08/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and previous versions allows remote authenticated users to execute arbitrary SQL commands via the customfieldlinkid parameter in a delcflink action.

Vulnerable Product Search on Vulmon Subscribe to Product

kayako supportsuite 3.10.00

kayako supportsuite 3.11.01

kayako supportsuite

kayako supportsuite 3.10.02

kayako supportsuite 3.11.00

Exploits

source: wwwsecurityfocuscom/bid/30642/info Kayako SupportSuite is prone to multiple input-validation vulnerabilities, including an SQL-injection issue, multiple cross-site scripting issues, and an HTML-injection issue The vulnerabilities occur because the application fails to sufficiently sanitize user-supplied data Exploiting thes ...