4.3
CVSSv2

CVE-2009-4433

Published: 28/12/2009 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 445
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (a) 5 or (b) 9 field in a post action to ticket_function.php, reachable through ticket_submit.php and index.php; (c) the which parameter to function.php, or (d) the which parameter to index.php, related to knowledgebase_list.php. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

idevspot isupport 1.02

idevspot isupport

idevspot isupport 1.06

Exploits

source: wwwsecurityfocuscom/bid/37380/info iDevSpot iSupport is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied input An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site ...
source: wwwsecurityfocuscom/bid/37380/info iDevSpot iSupport is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied input An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected si ...
--------------------------------------------- ++ iSupport <= 18 ++ XSS/Local File Include Exploit --------------------------------------------- Discovered by : Stink' & Essandre DATE : 16/12/09 ////////////////////////////////////////////////////////////////////// Website : wwwidevspotcom/ DEMO : wwwidevspotcom/demo/iS ...