[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-4433Date: (C)2009-12-28   (M)2023-12-22


Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (a) 5 or (b) 9 field in a post action to ticket_function.php, reachable through ticket_submit.php and index.php; (c) the which parameter to function.php, or (d) the which parameter to index.php, related to knowledgebase_list.php. NOTE: some of these details are obtained from third party information.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
EXPLOIT-DB-10478
BID-37380
SECUNIA-37726
OSVDB-61109
OSVDB-61111
OSVDB-61112
http://packetstormsecurity.org/0912-exploits/isupport-lfixss.txt
isupport-index-function-xss(54859)
isupport-ticketfunction-xss(54858)

CPE    2
cpe:/a:idevspot:isupport:1.02
cpe:/a:idevspot:isupport:1.06
CWE    1
CWE-79

© SecPod Technologies