Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kayako SupportSuite 3.00.26 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) nav parameter in the downloads module, (2) Full Name and (3) Email fields in the core module, (4) Full Name, (5) Email, and (6) Subject fields in the tickets module, or (7) Registered Email field in the lostpassword feature in the core module.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2006-01-09T23:00:00
Updated: 2024-08-07T23:53:28.584Z
Reserved: 2006-01-09T00:00:00
Link: CVE-2005-4637
Vulnrichment
No data.
NVD
Status : Modified
Published: 2005-12-31T05:00:00.000
Modified: 2024-11-21T00:04:48.493
Link: CVE-2005-4637
Redhat
No data.