CVE-2005-2461
Kayako liveResponse 2.x - SQL Injection via Calendar Year or Date Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-2461. PoCs published by GulfTech Security.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Kayako LiveResponse by injecting UNION-based queries to extract username and password from the lrUsers table. The attack leverages improper input validation in the date, month, and year parameters.
Description
Multiple SQL injection vulnerabilities in the calendar feature in Kayako liveResponse 2.x allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) date parameter.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in Kayako LiveResponse by injecting UNION-based queries to extract username and password from the lrUsers table. The attack leverages improper input validation in the date, month, and year parameters.