CVE-2004-1413
Kayako eSupport 2.x - SQL Injection via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1413. PoCs published by GulfTech Security.
AI-analyzed exploit summary This is a writeup describing multiple input validation vulnerabilities in Kayako eSupport, including cross-site scripting and six SQL injection vulnerabilities. It provides URLs with injection points but does not include executable exploit code.
Description
Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat, (2) rate, (3) questiondetails, (4) ticketkey22, (5) email22 parameters to index.php, or (6) the e-mail field of the Forgot Key feature.
Exploits (1)
This is a writeup describing multiple input validation vulnerabilities in Kayako eSupport, including cross-site scripting and six SQL injection vulnerabilities. It provides URLs with injection points but does not include executable exploit code.