CVE-2004-1412
Kayako eSupport 2.x - Cross-Site Scripting via index.php searchm Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1412. PoCs published by GulfTech Security.
AI-analyzed exploit summary The provided text describes multiple input validation vulnerabilities in Kayako eSupport, including cross-site scripting (XSS) and SQL injection (SQLi) flaws. It references a specific URL parameter (`searchm`) that is vulnerable to exploitation but does not include actual exploit code.
Description
Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.x allows remote attackers to inject arbitrary web script or HTML via the searchm parameter.
Exploits (1)
The provided text describes multiple input validation vulnerabilities in Kayako eSupport, including cross-site scripting (XSS) and SQL injection (SQLi) flaws. It references a specific URL parameter (`searchm`) that is vulnerable to exploitation but does not include actual exploit code.