CVE-2005-0842
Kayako eSupport 2.3 - Cross-Site Scripting via _i or _c Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-0842. PoCs published by GulfTech Security.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Kayako ESupport 2.3, where multiple parameters in the 'index.php' script can be exploited to inject malicious HTML and script code. The vulnerability allows for theft of cookie-based authentication credentials or other attacks.
Description
Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) _i or (2) _c parameter.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in Kayako ESupport 2.3, where multiple parameters in the 'index.php' script can be exploited to inject malicious HTML and script code. The vulnerability allows for theft of cookie-based authentication credentials or other attacks.