First published: Fri Dec 31 2004(Updated: )
Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat, (2) rate, (3) questiondetails, (4) ticketkey22, (5) email22 parameters to index.php, or (6) the e-mail field of the Forgot Key feature.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kayako eSupport | =2.1.8 | |
Kayako eSupport | =2.2 | |
Kayako eSupport | =2.3 | |
Kayako eSupport | =2.1.2 | |
Kayako eSupport | =2.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.