PoC Index

CVE-2004-1413

MEDIUM 5.0EPSS 1.1%

Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat, (2) rate, (3) questiondetails, (4) ticketkey22, (5) email22 parameters to index.php, or (6) the e-mail field of the Forgot Key feature.

CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.10% chance of exploitation in the next 30 days, 63th percentile
Published
2005-02-12
Updated
2024-08-08

ExploitDB entries (1)

References

Related