Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a (1) lostpassword or (2) register action in index.php, (3) unspecified vectors in the Submit form in a submit action in index.php, and (4) the user's name in index.php; and (5) allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the Admin and Staff Control Panel. NOTE: this might issue overlap CVE-2004-1412, CVE-2005-0487, or CVE-2005-0842.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kayako | Esupport | 3.00.13 |
Related Weaknesses (CWE)
References
- http://osvdb.org/33535
- http://osvdb.org/33536
- http://secunia.com/advisories/24223Vendor Advisory
- http://securityreason.com/securityalert/2335
- http://www.securityfocus.com/archive/1/460591/100/0/threaded
- http://www.securityfocus.com/bid/22631
- http://www.vupen.com/english/advisories/2007/0717
- http://osvdb.org/33535
- http://osvdb.org/33536
- http://secunia.com/advisories/24223Vendor Advisory
- http://securityreason.com/securityalert/2335
- http://www.securityfocus.com/archive/1/460591/100/0/threaded
- http://www.securityfocus.com/bid/22631
- http://www.vupen.com/english/advisories/2007/0717
FAQ
What is CVE-2007-1145?
CVE-2007-1145 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related ...
How severe is CVE-2007-1145?
CVE-2007-1145 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-1145?
Check the references section above for vendor advisories and patch information. Affected products include: Kayako Esupport.