SupportSuite 3.11.01~ Multiple file ~ PHP SELF XSS
Posted by imei on December 6th, 2007——-Summary——
Software: SupportSuite
Sowtware’s Web Site: http://www.kayako.com
Versions: 3.00.32
Class: Remote
Status: Unpatched
Exploit: Available
Solution: Not Available
Discovered by: imei Addmimistrator
Risk Level: Medium
——Description—–
Supportsuite , a great product of kayako, Ideal for providing ticket based support, is prone to XSS attack in multiple internal files.{more than 300 files}
Use of unsafe variable PHP_SELF in so many files of supprtsuite, makes this program vulnerable against […]