Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Kayako LiveResponse Multiple Input Validation Vulnerabilities

Kayako LiveResponse is prone to multiple cross-site scripting, SQL injection, and HTML injection vulnerabilties. These issues are all related to input validation errors.

The cross-site scripting and HTML injection vulnerabilities may allow for theft of cookie-based authentication credentials or other attacks. The SQL injection vulnerabilities may permit a remote attacker to compromise the software or launch attacks other attacks against the database.







 

Privacy Statement
Copyright 2009, SecurityFocus