CVE Vulnerabilities

CVE-2004-1413

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat, (2) rate, (3) questiondetails, (4) ticketkey22, (5) email22 parameters to index.php, or (6) the e-mail field of the Forgot Key feature.

Affected Software

NameVendorStart VersionEnd Version
EsupportKayako2.1.2 (including)2.1.2 (including)
EsupportKayako2.1.8 (including)2.1.8 (including)
EsupportKayako2.2 (including)2.2 (including)
EsupportKayako2.2.5 (including)2.2.5 (including)
EsupportKayako2.3 (including)2.3 (including)

References